A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. | |
| Title | Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection | |
| First Time appeared |
Totolink
Totolink n300rh Firmware |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:o:totolink:n300rh_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink
Totolink n300rh Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-27T05:32:15.135Z
Reserved: 2026-02-26T20:33:00.808Z
Link: CVE-2026-3301
No data.
Status : Received
Published: 2026-02-27T06:18:00.480
Modified: 2026-02-27T06:18:00.480
Link: CVE-2026-3301
No data.
OpenCVE Enrichment
No data.