Impact
The vulnerability arises from a stack-based buffer overflow in the setWiFiBasicConfig function within the Web Management Interface of Totolink N300RH component wireless.so. Manipulating the KeyStr argument allows an attacker to corrupt the stack and potentially execute arbitrary code. The weakness is identified as CWE-119 and CWE-121, which typically enable remote code execution and unpredictable program behavior.
Affected Systems
The affected device is the Totolink N300RH router running firmware version 6.1c.1353_B20190305. No additional vendor/product versions are listed as affected.
Risk and Exploitability
With a CVSS score of 9.3, this vulnerability is classified as critical. Although the EPSS score is not available, the fact that the exploit is public and can be carried out remotely indicates a high likelihood of real-world exploitation. The vulnerability is not listed in the CISA KEV catalog, but its severity and remote nature make it a high‑priority threat.
OpenCVE Enrichment