CVE-2026-1158: Totolink LR350 POST Request cstecgi.cgi setWizardCfg buffer overflow
A security flaw has been discovered in Totolink LR350 9.3.5u.6369B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1158?
CVE-2026-1158 has a critical severity rating due to its potential for buffer overflow exploitation.
How do I fix CVE-2026-1158?
To fix CVE-2026-1158, update your Totolink LR350 firmware to the latest version provided by the manufacturer.
What does CVE-2026-1158 affect?
CVE-2026-1158 affects the 'setWizardCfg' function within the cstecgi.cgi file of the Totolink LR350 router.
What can an attacker do with CVE-2026-1158?
An attacker could exploit CVE-2026-1158 to execute arbitrary code or perform unauthorized actions on the affected device.
Is my device vulnerable if it runs an unpatched version of Totolink LR350?
Yes, running an unpatched version of Totolink LR350 makes your device vulnerable to the exploits associated with CVE-2026-1158.