Unrated severityNVD Advisory· Published Jan 19, 2026· Updated Feb 23, 2026
Totolink LR350 cstecgi.cgi setWiFiBasicCfg buffer overflow
CVE-2026-1156
Description
A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected products
1- cpe:2.3:o:totolink:lr350_firmware:*:*:*:*:*:*:*:*Range: 9.3.5u.6369_B20220309
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lavender-bicycle-a5a.notion.site/TOTOLINK-LR350-setWiFiBasicCfg-2e453a41781f80a2ad43e85bf5d46659mitreexploit
- vuldb.commitrethird-party-advisory
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entrytechnical-description
- www.totolink.netmitreproduct
News mentions
0No linked articles in our index yet.