CVE-2026-4976: Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
A vulnerability was found in Totolink LR350 9.3.5u.6369B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4976?
The severity of CVE-2026-4976 is classified as high due to the potential for remote code execution through buffer overflow.
How do I fix CVE-2026-4976?
To fix CVE-2026-4976, update the Totolink LR350 firmware to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2026-4976?
CVE-2026-4976 affects the Totolink LR350 running version 9.3.5u.6369_B20220309.
What is the impact of CVE-2026-4976?
The impact of CVE-2026-4976 includes potential remote exploitation leading to unauthorized access or control over the affected device.
How can attackers exploit CVE-2026-4976?
Attackers can exploit CVE-2026-4976 by sending specially crafted requests to the setWiFiGuestCfg function, leading to a buffer overflow.