6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Basic Information
ID
CVE-2026-6158
Source
VulDB
Published
Apr 13, 2026 at 04:00
Affected Product
Vendor
Totolink
Product
N300RH
Version
6.1c.1353_B20190305
Affected Versions
Totolink N300RH 6.1c.1353_B20190305