Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-7748

Опубликовано: 04 мая 2026
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument FileName can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

EPSS

Процентиль: 38%
0.00463
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.8
github
3 месяца назад

A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument FileName can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 8.8
fstec
4 месяца назад

Уязвимость функции setUpgradeFW() сценария cgi-bin/cstecgi.cgi микропрограммного обеспечения маршрутизаторов TOTOLINK N300RH, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.00463
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119