CVE-2026-7750
8.8Totolink · N300RH
A buffer overflow vulnerability in the Totolink N300RH router allows remote attackers to execute arbitrary code via a malicious MAC address parameter.
Executive summary
A critical buffer overflow vulnerability in Totolink N300RH version 3.2.4-B20220812 allows remote attackers to compromise device integrity and potentially execute arbitrary code.
Vulnerability
This vulnerability is a buffer overflow (CWE-120) located in the setMacFilterRules function within the /cgi-bin/cstecgi.cgi component, triggered via manipulated mac_address arguments requiring low-privilege authentication over the network.
Business impact
A successful exploit of this buffer overflow could allow attackers to gain complete control over affected routers, leading to network disruption, interception of internal traffic, and potential pivoting into private local area networks. Based on the CVSS score of 8.8, the severity is high, reflecting the potential for total loss of confidentiality, integrity, and availability of the affected device.
Remediation
Immediate Action: Apply official vendor security firmware updates as soon as they are made available by Totolink.
Proactive Monitoring: Monitor network traffic for anomalous administrative login patterns and unusual POST requests directed at the /cgi-bin/cstecgi.cgi endpoint.
Compensating Controls: Restrict management interface access to trusted internal IP addresses and disable remote management entirely where feasible.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists via researcher documentation referenced in the advisory data.
Analyst recommendation
Administrators managing affected Totolink N300RH devices must treat this vulnerability with high priority due to the availability of public exploit references and the severity of potential device compromise. Implement immediate compensating controls by isolating management interfaces from the public internet while awaiting official vendor patches.
More Totolink CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.