Junglewise Threat Intelligence

CVE-2026-10187: Totolink N300RH stack overflow in setWiFiBasicConfig

CVE-2026-10187 · Severity: critical · CVSS 9.8 · Published 2026-05-31

Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink N300RH wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely exploit this flaw through the router's web management interface to gain full control over the device. This could lead to unauthorized access to network traffic, service disruptions, or the use of the router as a foothold for further attacks on the internal network.

Technical details

A stack-based buffer overflow vulnerability exists in the Totolink N300RH firmware version 6.1c.1353_B20190305. The flaw is located within the setWiFiBasicConfig function in the wireless.so library, which is part of the Web Management Interface component. By sending a specially crafted request containing a manipulated KeyStr argument, a remote, unauthenticated attacker can trigger the overflow. This can lead to arbitrary code execution or a denial-of-service (DoS) condition. Public exploit code is reportedly available.

Affected products

  • Totolink N300RH 6.1c.1353_B20190305

Timeline

  • 2026-05-31: advisory: NVD publication date

References

Related threats