Description
A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-01-19
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Apply patch
AI Analysis

Impact

The vulnerability originates from an unchecked buffer copy in the setWiFiBasicCfg function of /cgi-bin/cstecgi.cgi. An attacker can supply a malformed ssid argument that overflows a buffer, enabling arbitrary code execution on the device. The flaw is a classic buffer overflow (CWE‑119 and CWE‑120), allowing compromise of the router’s confidentiality, integrity, and availability.

Affected Systems

The flaw affects Totolink LR350 routers with firmware 9.3.5u.6369_B20220309. The specific asset is the cstecgi.cgi CGI script that handles wireless configuration through the web interface. Devices running this firmware version are vulnerable when exposed to the internet or to the local network.

Risk and Exploitability

CVSS score 8.7 indicates a high severity. The EPSS is below 1%, suggesting that the threat may not be widely exploited at present, and the vulnerability is not listed in the CISA KEV catalogue. Nevertheless, because the attack vector is remote and the flaw can be triggered via a standard Web request, the risk remains significant. An attacker who succeeds can execute code on the device and potentially take control of the network.

Generated by OpenCVE AI on April 18, 2026 at 05:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router to the latest firmware provided by Totolink that addresses CVE-2026-1156
  • If an update is not yet available, block remote access to /cgi-bin/cstecgi.cgi via firewall rules and disable remote management of the device
  • Ensure that the wireless SSID is configured securely and consider restricting access to the router’s web interface to trusted networks only

Generated by OpenCVE AI on April 18, 2026 at 05:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:totolink:lr350_firmware:*:*:*:*:*:*:*:*

Thu, 29 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink lr350 Firmware
CPEs cpe:2.3:h:totolink:lr350:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:lr350_firmware:9.3.5u.6369_b20220309:*:*:*:*:*:*:*
Vendors & Products Totolink lr350 Firmware

Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink lr350
Vendors & Products Totolink
Totolink lr350

Mon, 19 Jan 2026 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Title Totolink LR350 cstecgi.cgi setWiFiBasicCfg buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink Lr350 Lr350 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:46:20.106Z

Reserved: 2026-01-18T20:19:56.244Z

Link: CVE-2026-1156

cve-icon Vulnrichment

Updated: 2026-01-20T21:31:47.246Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-19T14:15:49.950

Modified: 2026-01-29T18:40:14.233

Link: CVE-2026-1156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T05:15:15Z

Weaknesses