CVE-2026-1155: Totolink LR350 cstecgi.cgi setWiFiEasyGuestCfg buffer overflow
A vulnerability was found in Totolink LR350 9.3.5u.6369B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1155?
CVE-2026-1155 is classified as a high severity vulnerability due to its potential for exploit through buffer overflow.
How do I fix CVE-2026-1155?
To fix CVE-2026-1155, update the Totolink LR350 firmware to the latest version that addresses this buffer overflow issue.
What systems are affected by CVE-2026-1155?
CVE-2026-1155 affects the Totolink LR350 router running version 9.3.5u.6369_B20220309.
What is the impact of exploiting CVE-2026-1155?
Exploiting CVE-2026-1155 could allow an attacker to execute arbitrary code or cause a denial of service on the affected device.
How can I detect if CVE-2026-1155 is present on my system?
You can detect CVE-2026-1155 by checking the firmware version of your Totolink LR350 device and looking for any signs of unusual behavior or performance issues.