Executive brief
A security vulnerability exists in the Totolink N300RT wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could lead to a complete loss of internet access or unauthorized access to network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the Totolink N300RT router (firmware version 3.4.0-B20250430) within the 'is_cmd_string_valid' function of the 'libapmib.so' library. The vulnerability is triggered when the '/boafrm/formWsc' endpoint processes the 'localPin' parameter. While the function filters for command injection characters, it fails to perform length validation before passing the input to an unsafe 'sprintf' call. An attacker with high privileges (or one who bypasses authentication via flawed sessionCheck logic) can send a specially crafted HTTP POST request to overwrite the saved return address on the stack, leading to a denial of service (service crash) or remote code execution. Proof-of-concept exploits are publicly available.
Affected products
- Totolink N300RT 3.4.0-B20250430
Timeline
- 2026-04-28: disclosed: Initial public disclosure and NVD publication
- 2026-04-28: advisory