CVE-2026-7749

8.8

Totolink · N300RH

A buffer overflow vulnerability in Totolink N300RH allows remote authenticated attackers to execute arbitrary code via the priDns parameter.

Executive summary

A buffer overflow vulnerability affects Totolink N300RH version 3.2.4-B20220812, creating a high-severity risk of remote code execution.

Vulnerability

This flaw involves a buffer overflow (CWE-120) located in the setWanConfig function within the /cgi-bin/cstecgi.cgi file of the POST Request Handler component, requiring low privileges for an attacker to trigger remotely.

Business impact

A successful exploit of this vulnerability could lead to total compromise of the affected router, allowing attackers to manipulate network traffic, intercept sensitive data, or disrupt business operations. The CVSS score of 8.8 reflects the high risk of complete system compromise via remote network exploitation.

Remediation

Immediate Action: Apply vendor security updates as soon as they become available or restrict administrative access to trusted internal networks only.

Proactive Monitoring: Monitor network devices for anomalous traffic patterns, unexpected reboots, or unauthorized configuration changes.

Compensating Controls: Implement strict network segmentation and firewall rules to limit exposure of the router management interface to the public internet.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced researcher write-up.

Analyst recommendation

Given the high CVSS score and the availability of a public proof-of-concept, administrators should treat this vulnerability with urgency. Mitigate exposure immediately by restricting remote access interfaces and applying patches as soon as the vendor provides them.

More Totolink CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.