Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

N300RH — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in N300RH, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the N300RH product, detailing specific software weaknesses and associated security tags. It collects reported flaws discovered within a defined historical timeframe, encompassing various classes of security defects found in the system’s architecture and operations. Readers can utilize this resource to track vendor-published advisories, analyze specific weakness categories, or review the complete vulnerability history of the N300RH to assess its long-term security posture. The data is presented objectively to support risk assessment and patch management activities without promotional commentary.

Vendor: TOTOLINK

CVE ID Title CVSS Severity Published
CVE-2026-10187 Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow CWE-121 9.8 Critical 2026-05-31
CVE-2026-9543 Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection CWE-78 9.8 Critical 2026-05-26
CVE-2026-7750 Totolink N300RH POST Request cstecgi.cgi setMacFilterRules buffer overflow CWE-120 8.8 High 2026-05-04
CVE-2026-7749 Totolink N300RH POST Request cstecgi.cgi setWanConfig buffer overflow CWE-120 8.8 High 2026-05-04
CVE-2026-7748 Totolink N300RH POST Request cstecgi.cgi setUpgradeFW buffer overflow CWE-120 8.8 High 2026-05-04
CVE-2026-7747 Totolink N300RH Parameter cstecgi.cgi loginauth buffer overflow CWE-120 9.8 Critical 2026-05-04
CVE-2026-7633 Totolink N300RH cstecgi.cgi setUploadSetting file inclusion CWE-73 6.5 Medium 2026-05-02
CVE-2026-6158 Totolink N300RH upgrade.so setUpgradeUboot os command injection CWE-78 7.3 High 2026-04-13
CVE-2026-3696 Totolink N300RH CGI cstecgi.cgi setWiFiWpsConfig os command injection CWE-78 7.3 High 2026-03-08
CVE-2026-3301 Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection CWE-78 9.8 Critical 2026-02-27
CVE-2025-6401 TOTOLINK N300RH HTTP POST Message formFilter denial of service CWE-404 3.5 Low 2025-06-21
CVE-2025-6400 TOTOLINK N300RH HTTP POST Message formPortFw buffer overflow CWE-120 8.8 High 2025-06-21
CVE-2025-4851 TOTOLINK N300RH cstecgi.cgi setUploadUserData command injection CWE-77 6.3 Medium 2025-05-18
CVE-2025-4850 TOTOLINK N300RH cstecgi.cgi setUnloadUserData command injection CWE-77 6.3 Medium 2025-05-18
CVE-2025-4849 TOTOLINK N300RH cstecgi.cgi CloudACMunualUpdateUserdata command injection CWE-77 6.3 Medium 2025-05-18

All 15 known CVE vulnerabilities affecting N300RH with full Chinese analysis, references, and POCs where available.