CVE-2026-6158
published 2026-04-13CVE-2026-6158: A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the…
PriorityP357high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
1.41%
69.6th percentile
A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | n300rh | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3cm3-qfjh-c5x9: A flaw has been found in Totolink N300RH 6
ghsa_unreviewed·2026-04-13
CVE-2026-6158 [MEDIUM] CWE-77 GHSA-3cm3-qfjh-c5x9: A flaw has been found in Totolink N300RH 6
A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
VulDB
Totolink N300RH 6.1c.1353_B20190305 upgrade.so setUpgradeUboot FileName os command injection
vuldb·2026-04-12·CVSS 6.9
CVE-2026-6158 [MEDIUM] Totolink N300RH 6.1c.1353_B20190305 upgrade.so setUpgradeUboot FileName os command injection
A vulnerability identified as critical has been detected in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection.
This vulnerability is tracked as CVE-2026-6158. The attack is possible to be carried out remotely. Moreover, an exploit is present.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-13
Published