CVE-2026-4976

8.8

Totolink · LR350

A buffer overflow vulnerability in the Totolink LR350 setWiFiGuestCfg function allows remote attackers to trigger memory corruption via the ssid argument.

Executive summary

A critical remote buffer overflow vulnerability in Totolink LR350 routers poses a severe risk of unauthorized system manipulation and potential service disruption.

Vulnerability

This vulnerability involves a buffer overflow in the setWiFiGuestCfg function within the /cgi-bin/cstecgi.cgi script. The flaw allows an authenticated attacker to trigger memory corruption by injecting a malicious ssid argument, which can be executed remotely.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high level of severity. Successful exploitation could lead to total system compromise, resulting in unauthorized access to sensitive network settings, potential service outages, or the ability for an attacker to persist within the local network environment.

Remediation

Immediate Action: Since a specific patch is not currently identified, administrators should restrict management access to the device and disable guest Wi-Fi features until the vendor releases a firmware update.

Proactive Monitoring: Monitor device access logs for unusual traffic patterns targeting the /cgi-bin/cstecgi.cgi endpoint, specifically looking for abnormally long strings within the ssid parameter.

Compensating Controls: Deploy a Web Application Firewall (WAF) or intrusion prevention system to filter and block requests containing oversized payloads directed at the vulnerable cstecgi.cgi script.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the researcher at the referenced Notion link.

Analyst recommendation

Given the availability of a public proof-of-concept and the potential for total system impact, this vulnerability requires immediate attention. Security teams should prioritize isolating affected Totolink devices from the public internet and applying forthcoming vendor firmware updates as soon as they are released to prevent potential exploitation.

More Totolink CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.