CVE-2026-7748
8.8Totolink · N300RH
A buffer overflow vulnerability in Totolink N300RH version 3.2.4-B20220812 allows remote authenticated attackers to execute arbitrary code via the FileName argument in the setUpgradeFW function.
Executive summary
A critical buffer overflow vulnerability in the Totolink N300RH router allows remote attackers to achieve full system compromise through the firmware upgrade handler.
Vulnerability
This flaw is a buffer overflow (CWE-120) located within the setUpgradeFW function of the /cgi-bin/cstecgi.cgi component, triggered by manipulating the FileName argument. The attack can be launched remotely by a low-privileged authenticated user with no user interaction required.
Business impact
A successful exploit of this vulnerability can lead to total loss of confidentiality, integrity, and availability on the affected device, potentially allowing an adversary to take complete control of the router. Given the CVSS score of 8.8, this high severity rating reflects the severe impact on device stability and network security, potentially compromising the entire local network segment behind the device.
Remediation
Immediate Action: Apply vendor firmware updates as soon as they become available from Totolink, or restrict administrative interface access to trusted internal management networks only.
Proactive Monitoring: Monitor network traffic and device logs for anomalous administrative login sessions and unexpected restarts of the Totolink N300RH device.
Compensating Controls: Implement strict network segmentation and firewall rules to prevent unauthorized or untrusted remote access to the router management interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept reference exists from the vulnerability disclosure.
Analyst recommendation
Security teams managing Totolink N300RH routers must treat this vulnerability with high urgency due to the potential for complete device compromise. Administrators should immediately check for firmware patches, restrict management access, and monitor device logs closely until an official fix is applied.
More Totolink CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.