Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-3301

Опубликовано: 27 фев. 2026
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:totolink:n300rh_firmware:6.1c.1349_b20181018:*:*:*:*:*:*:*
cpe:2.3:o:totolink:n300rh_firmware:6.1c.1353_b20190305:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n300rh:4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.04028
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 9.8
github
6 месяцев назад

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 9.8
fstec
6 месяцев назад

Уязвимость функции setWebWlanIdx микропрограммного обеспечения маршрутизаторов TOTOLINK N300RH, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 89%
0.04028
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-77
CWE-78