VYPR
High severity8.8NVD Advisory· Published Jan 19, 2026· Updated Jun 17, 2026

CVE-2026-1158

CVE-2026-1158

Description

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:o:totolink:lr350_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:totolink:lr350_firmware:*:*:*:*:*:*:*:*range: 9.3.5u.6369_B20220309
    • cpe:2.3:o:totolink:lr350_firmware:9.3.5u.6369_b20220309:*:*:*:*:*:*:*
  • Totolink/LR350llm-fuzzy
    Range: 9.3.5u.6369_B20220309

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.