Vulnerability Description
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | Lr350 Firmware | 9.3.5u.6369_b20220309 |
| Totolink | Lr350 | - |
Related Weaknesses (CWE)
References
- https://lavender-bicycle-a5a.notion.site/TOTOLINK-LR350-setWiFiEasyCfg-2e453a417ExploitThird Party Advisory
- https://vuldb.com/?ctiid.341751Permissions RequiredVDB Entry
- https://vuldb.com/?id.341751Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.735726Third Party AdvisoryVDB Entry
- https://www.totolink.net/Product
FAQ
What is CVE-2026-1157?
CVE-2026-1157 is a vulnerability with a CVSS score of 8.8 (HIGH). A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffe...
How severe is CVE-2026-1157?
CVE-2026-1157 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1157?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink Lr350 Firmware, Totolink Lr350.