Description
A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-01-18: | Advisory disclosed |
| 2026-01-18: | VulDB entry created |
| 2026-01-20: | VulDB entry last update |
Credits
wxhwxhwxh_tutu (VulDB User)
References
vuldb.com/?id.341750 (VDB-341750 | Totolink LR350 cstecgi.cgi setWiFiBasicCfg buffer overflow)
vuldb.com/?ctiid.341750 (VDB-341750 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.735722 (Submit #735722 | TOTOLINK LR350 LR350 V9.3.5u.6369_B20220309 Buffer Overflow)
lavender-bicycle-a5a.notion.site/...5d46659?source=copy_link
www.totolink.net/