Junglewise Threat Intelligence

CVE-2026-9543: Totolink N300RH command injection in setPasswordCfg

CVE-2026-9543 · Severity: critical · CVSS 9.8 · Published 2026-05-26

Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink N300RH wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take full control of the router without needing a password. This could allow them to intercept internet traffic, disrupt network services, or use the device as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink N300RH router (firmware version 6.1c.1353_B20190305) within the Web Management Interface. The flaw is located in the 'setPasswordCfg' function of the '/cgi-bin/cstecgi.cgi' component. By manipulating the 'admpass' argument in a specially crafted request, a remote, unauthenticated attacker can execute arbitrary system commands on the underlying operating system. This occurs due to improper neutralization of special elements used in an OS command. The exploit has been disclosed publicly.

Affected products

  • Totolink N300RH 6.1c.1353_B20190305

Timeline

  • 2026-05-26: disclosed: Vulnerability disclosed and CVE assigned
  • 2026-05-26: advisory: NVD published the vulnerability record

References

Related threats