CVE-2026-7717

8.8

Totolink · WA300

A buffer overflow vulnerability in Totolink WA300 allows remote authenticated attackers to execute arbitrary code via the File argument in the UploadCustomModule function.

Executive summary

A buffer overflow vulnerability in the Totolink WA300 router allows remote attackers to achieve total system compromise by manipulating the File argument within the UploadCustomModule function.

Vulnerability

This flaw is classified as a buffer overflow (CWE-120) and memory corruption issue residing in the UploadCustomModule function of the /cgi-bin/cstecgi.cgi component, requiring low privileges (authenticated user) and network access to trigger.

Business impact

A successful exploit of this vulnerability can result in total system compromise, including loss of confidentiality, integrity, and availability of the affected networking device. Given the CVSS score of 8.8, an attacker could potentially intercept network traffic, pivot to internal network segments, or render the device inoperable, posing a severe risk to organizational operations and network security.

Remediation

Immediate Action: Apply official firmware updates from Totolink as soon as they become available, or restrict management interface access to trusted internal networks only.

Proactive Monitoring: Monitor device access logs and network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi involving the UploadCustomModule function.

Compensating Controls: Implement strict network segmentation and place vulnerable devices behind a firewall or VPN to prevent unauthorized remote access to the management interface.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as referenced in the vendor vulnerability advisory and security research write-up.

Analyst recommendation

This vulnerability presents a high risk due to the potential for remote code execution and total system compromise on affected networking hardware. Administrators must prioritize restricting administrative access to trusted management networks and apply vendor patches immediately upon release to secure the environment against potential exploitation.

More Totolink CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.