PT-2026-3432 · Totolink · Totolink Lr350

·

CVE-2026-1149

·

Publicado

2025-01-10

·

Atualizado

2026-01-29

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink LR350 version 9.3.5u.6369 B20220309
Description A flaw exists in the Totolink LR350 device. This issue is located within the setDiagnosisCfg function of the /cgi-bin/cstecgi.cgi file, part of the POST Request Handler component. Manipulation of the ip argument can result in command injection. The attack can be initiated remotely. The exploit is publicly available.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /cgi-bin/cstecgi.cgi file.

Exploit

Correção

Command Injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00612
CVE-2026-1149

Produtos afetados

Totolink Lr350