TOTOLINK LR350是中国吉翁电子(TOTOLINK)公司的一款无线路由器。 TOTOLINK LR350 9.3.5u.6369_B20220309版本存在命令注入漏洞,该漏洞源于对文件/cgi-bin/cstecgi.cgi中参数ip的错误操作,可能导致命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-1158 | 8.8 HIGH | Totolink LR350 POST Request cstecgi.cgi setWizardCfg buffer overflow |
| CVE-2026-1157 | 8.8 HIGH | Totolink LR350 cstecgi.cgi setWiFiEasyCfg buffer overflow |
| CVE-2026-1156 | 8.8 HIGH | Totolink LR350 cstecgi.cgi setWiFiBasicCfg buffer overflow |
| CVE-2026-1155 | 8.8 HIGH | Totolink LR350 cstecgi.cgi setWiFiEasyGuestCfg buffer overflow |
| CVE-2026-1143 | 8.8 HIGH | TOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg buffer overflow |
| CVE-2026-1150 | 6.3 MEDIUM | Totolink LR350 POST Request cstecgi.cgi setTracerouteCfg command injection |
No comments yet