CVE-2026-3301: Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection
A security flaw has been discovered in Totolink N300RH 6.1c.1353B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3301?
CVE-2026-3301 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-3301?
To mitigate CVE-2026-3301, update the Totolink N300RH firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2026-3301?
CVE-2026-3301 is an OS command injection vulnerability found in the web management interface of the Totolink N300RH router.
Which product is affected by CVE-2026-3301?
CVE-2026-3301 affects the Totolink N300RH router specifically in version 6.1c.1353_B20190305.
What are the potential risks of CVE-2026-3301?
Exploiting CVE-2026-3301 could allow an attacker to execute arbitrary commands on the affected router, compromising its security.