Description
A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument http_host results in buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
Timeline
| 2026-05-03: | Advisory disclosed |
| 2026-05-03: | VulDB entry created |
| 2026-05-03: | VulDB entry last update |
Credits
wxhwxhwxh_mie (VulDB User)
References
vuldb.com/vuln/360895 (VDB-360895 | Totolink WA300 POST Request cstecgi.cgi loginauth buffer overflow)
vuldb.com/vuln/360895/cti (VDB-360895 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/807197 (Submit #807197 | Totolink WA300 WA300 V5.2cu.7112_B20190227 Buffer Overflow)
lavender-bicycle-a5a.notion.site/...781f8050b8ffc9e90a103cd5
www.totolink.net/