peter bassill · operator
$ cve CVE-2026-3301 JSON

CVE-2026-3301

9.8
CRITICAL · CVSS 3.1 · EPSS 4.5% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.51% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2026-02-27
Last modified2026-06-17

Affected (2)

VendorProduct
totolinkn300rh
totolinkn300rh firmware

References

→ the Explorer  ·  watch your stack  ·  NVD