CVE 6.9 MEDIUM

Totolink N300RH upgrade.so setUpgradeUboot os command injection_CVE-2026-6158

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Basic Information

ID CVE-2026-6158
Source VulDB
Published Apr 13, 2026 at 04:00

Affected Product

Vendor Totolink
Product N300RH
Version 6.1c.1353_B20190305
Affected Versions Totolink N300RH 6.1c.1353_B20190305

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.