Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

N300RH — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in N300RH, with AI-generated Chinese analysis, references, and POCs.

This document serves as the vulnerability aggregation page for vendor N300RH, focusing on product N300RH and covering general software weakness categories. The page collects a comprehensive range of security issues identified within the N300RH firmware and software stack, spanning from initial discovery through to resolved patches. This collection includes critical remote code execution flaws, privilege escalation bugs, and data exposure vulnerabilities that have been reported or verified by security researchers and the vendor over the past decade. By centralizing this data, the resource aims to provide transparency and clarity regarding the security posture of N300RH. Readers can use this page to track the vendor’s historical advisory releases and understand the evolution of their patching practices. It also allows security professionals to analyze specific weakness classes affecting the product, helping them assess risk profiles for deployments. Furthermore, users can look up the detailed vulnerability history of N300RH to identify recurring patterns or systemic design flaws that may persist across multiple versions. This aggregated view supports informed decision-making for IT administrators, security auditors, and developers who rely on N300RH infrastructure. The information is structured to facilitate quick reference and deep analysis without overwhelming the user with raw data feeds. Ultimately, this page acts as a centralized reference point for understanding the security landscape surrounding N300RH.

Vendor: TOTOLINK

CVE IDTitleCVSSSeverityPublished
CVE-2026-10187 Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow CWE-121 9.8 Critical2026-05-31
CVE-2026-9543 Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection CWE-78 9.8 Critical2026-05-26
CVE-2026-7750 Totolink N300RH POST Request cstecgi.cgi setMacFilterRules buffer overflow CWE-120 8.8 High2026-05-04
CVE-2026-7749 Totolink N300RH POST Request cstecgi.cgi setWanConfig buffer overflow CWE-120 8.8 High2026-05-04
CVE-2026-7748 Totolink N300RH POST Request cstecgi.cgi setUpgradeFW buffer overflow CWE-120 8.8 High2026-05-04
CVE-2026-7747 Totolink N300RH Parameter cstecgi.cgi loginauth buffer overflow CWE-120 9.8 Critical2026-05-04
CVE-2026-7633 Totolink N300RH cstecgi.cgi setUploadSetting file inclusion CWE-73 6.5 Medium2026-05-02
CVE-2026-6158 Totolink N300RH upgrade.so setUpgradeUboot os command injection CWE-78 7.3 High2026-04-13
CVE-2026-3696 Totolink N300RH CGI cstecgi.cgi setWiFiWpsConfig os command injection CWE-78 7.3 High2026-03-08
CVE-2026-3301 Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection CWE-78 9.8 Critical2026-02-27
CVE-2025-6401 TOTOLINK N300RH HTTP POST Message formFilter denial of service CWE-404 3.5 Low2025-06-21
CVE-2025-6400 TOTOLINK N300RH HTTP POST Message formPortFw buffer overflow CWE-120 8.8 High2025-06-21
CVE-2025-4851 TOTOLINK N300RH cstecgi.cgi setUploadUserData command injection CWE-77 6.3 Medium2025-05-18
CVE-2025-4850 TOTOLINK N300RH cstecgi.cgi setUnloadUserData command injection CWE-77 6.3 Medium2025-05-18
CVE-2025-4849 TOTOLINK N300RH cstecgi.cgi CloudACMunualUpdateUserdata command injection CWE-77 6.3 Medium2025-05-18

All 15 known CVE vulnerabilities affecting N300RH with full Chinese analysis, references, and POCs where available.