Severity
7.4HIGH
EPSS
0.2%
top 62.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19

Description

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5totolink/lr3509.3.5u.6369_B20220309
NVDtotolink/lr350_firmware9.3.5u.6369_b20220309

🔴Vulnerability Details

2
CVEList
Totolink LR350 POST Request cstecgi.cgi setWizardCfg buffer overflow2026-01-19
GHSA
GHSA-27xh-5cf4-q5gc: A security flaw has been discovered in Totolink LR350 92026-01-19
CVE-2026-1158 (HIGH CVSS 7.4) | A security flaw has been discovered | cvebase.io