CVE-2026-1157
published 2026-01-19CVE-2026-1157: A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such…
PriorityP266high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.01%
61.6th percentile
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | lr350 | — | — |
| totolink | lr350_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
ghsa·2026-07-22
CVE-2026-10051 [MEDIUM] CWE-200 Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
### Description
> FINDING — MEDIUM (HTTP/1.1 keep-alive connections with trailers)
> HttpConnection._trailers Cross-Request Leakage (Never Reset Between Requests)
>
> Location:
> jetty-core/jetty-server/src/main/java/org/eclipse/jetty/server/internal/
> HttpConnection.java:107, 1157-1161, 1170
>
> Detail:
> _trailers (line 107) is a connection-scoped HttpFields.Mutable field.
> parsedTrailer() (line 1157) populates it when request N carries HTTP trailers.
> messageComplete() (line 1170) checks "if (_trailers != null)" — evaluates true
> from request N's data — and stamps it onto request N+1.
>
> Grep confirms: ZERO occurrences of "_trailers = null" in entire HttpConnection.java.
>
> Scenario:
> Request N
GHSA
GHSA-qc9v-jx78-g7ph: A vulnerability was identified in Totolink LR350 9
ghsa_unreviewed·2026-01-19
CVE-2026-1157 [HIGH] CWE-119 GHSA-qc9v-jx78-g7ph: A vulnerability was identified in Totolink LR350 9
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
No detection rules found.
No public exploits indexed.
2026-01-19
Published