Junglewise Threat Intelligence

CVE-2026-7219: Totolink N300RT buffer overflow in /boafrm/formIpQoS

CVE-2026-7219 · Severity: high · CVSS 7.2 · Published 2026-04-28

Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink N300RT wireless router, a device used to provide internet connectivity for homes and small offices. An attacker with administrative access can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow exists in the boa web server of the Totolink N300RT router (firmware version 3.4.0-B20250430). The vulnerability is located in the /boafrm/formIpQoS endpoint and is caused by the insecure use of the strcpy function when processing the 'entry_name' parameter. Although this parameter is hidden in the web UI, the backend binary fails to perform length validation before copying the input into a 192-byte local stack buffer. An authenticated attacker can send a crafted POST request with an 'entry_name' exceeding 324 bytes to overwrite the saved return address ($ra), leading to a crash (DoS) or potential remote code execution (RCE). A public proof-of-concept exploit has been released.

Affected products

  • Totolink N300RT 3.4.0-B20250430

Timeline

  • 2026-04-28: disclosed: Initial disclosure and publication of CVE-2026-7219

References

Related threats