Description
A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-02-27
Score: 9.3 Critical
EPSS: 4.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the setWebWlanIdx argument of /cgi-bin/cstecgi.cgi, a component of the router’s web management interface. An attacker can alter this parameter to inject arbitrary operating‑system commands that the device executes with elevated privileges. The attack does not require local access; it can be triggered remotely by sending a malicious HTTP request. This results in full compromise of the router, enabling the attacker to run any command, modify firmware, or use the device as a pivot point for further attacks. The weakness is an OS command injection, categorized as CWE‑77 and CWE‑78.

Affected Systems

Only the Totolink N300RH model running firmware version 6.1c.1353_B20190305 is explicitly listed as vulnerable. Based on the description, it is unclear whether earlier firmware releases contain the same flaw; the vulnerability is documented solely for this revision.

Risk and Exploitability

The CVSS score of 9.3 marks the issue as critical, emphasizing the remote execution capability with full device privileges. An EPSS score of 4% indicates a moderate likelihood of exploitation in the wild, especially after the release of public proof‑of‑concept code. The vulnerability is not yet in the CISA KEV catalog, but its remote nature and lack of built‑in mitigation suggest a high priority for immediate action to prevent compromise.

Generated by OpenCVE AI on June 18, 2026 at 10:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the firmware to a version that removes the vulnerable cstecgi.cgi script
  • If a firmware update cannot be applied immediately, block external access to the Web Management Interface with firewall rules or by isolating the router to a local network segment
  • If remote administration is not required, disable the web management feature entirely in the router configuration
  • Where possible, enforce strict numeric input on the webWlanIdx parameter to limit values to the expected range (CWE‑78)

Generated by OpenCVE AI on June 18, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 27 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink n300rh
CPEs cpe:2.3:h:totolink:n300rh:4.0:*:*:*:*:*:*:*
cpe:2.3:o:totolink:n300rh_firmware:6.1c.1349_b20181018:*:*:*:*:*:*:*
cpe:2.3:o:totolink:n300rh_firmware:6.1c.1353_b20190305:*:*:*:*:*:*:*
Vendors & Products Totolink n300rh

Fri, 27 Feb 2026 05:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Title Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection
First Time appeared Totolink
Totolink n300rh Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:n300rh_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink n300rh Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink N300rh N300rh Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-27T18:53:12.387Z

Reserved: 2026-02-26T20:33:00.808Z

Link: CVE-2026-3301

cve-icon Vulnrichment

Updated: 2026-02-27T18:53:09.084Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-27T06:18:00.480

Modified: 2026-06-17T10:43:22.387

Link: CVE-2026-3301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T10:45:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')