Description
A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument mac_address results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-05-03: | Advisory disclosed |
| 2026-05-03: | VulDB entry created |
| 2026-05-03: | VulDB entry last update |
Credits
wxhwxhwxh_mie (VulDB User)
References
vuldb.com/vuln/360925 (VDB-360925 | Totolink N300RH POST Request cstecgi.cgi setMacFilterRules buffer overflow)
vuldb.com/vuln/360925/cti (VDB-360925 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/807204 (Submit #807204 | Totolink N300RH N300RH V3_Firmware V3.2.4-B20220812 Buffer Overflow)
lavender-bicycle-a5a.notion.site/...781f809cb952cdcb71ce90d8
www.totolink.net/