N300RH
Totolink- Software type
- —
- Catalog vulnerabilities
- 15
Severity across 7 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 7 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 15 vulnerability records affecting N300RH.
Among the 7 records analyzed by CyStack, 6 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-10187Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/31/2026 | SeverityCritical |
CVE-2026-9543Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/26/2026 | SeverityCritical |
CVE-2026-7750Totolink N300RH POST Request cstecgi.cgi setMacFilterRules buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/04/2026 | SeverityHigh |
CVE-2026-7749Totolink N300RH POST Request cstecgi.cgi setWanConfig buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/04/2026 | SeverityHigh |
CVE-2026-7748Totolink N300RH POST Request cstecgi.cgi setUpgradeFW buffer overflow | Exploitation statusPublic exploit | FixYes | Published05/04/2026 | SeverityHigh |
CVE-2026-7747Totolink N300RH Parameter cstecgi.cgi loginauth buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/04/2026 | SeverityCritical |
CVE-2026-7633Totolink N300RH cstecgi.cgi setUploadSetting file inclusion | Exploitation statusPublic exploit | FixNot confirmed | Published05/02/2026 | SeverityMedium |
CVE-2026-6158Totolink N300RH upgrade.so setUpgradeUboot os command injection | Exploitation statusPublic exploit | FixYes | Published04/13/2026 | SeverityMedium |
CVE-2026-3696Totolink N300RH CGI cstecgi.cgi setWiFiWpsConfig os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published03/08/2026 | SeverityMedium |
CVE-2026-3301Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published02/27/2026 | SeverityCritical |
CVE-2025-6401TOTOLINK N300RH HTTP POST Message formFilter denial of service | Exploitation statusPublic exploit | FixNot confirmed | Published06/21/2025 | SeverityMedium |
CVE-2025-6400TOTOLINK N300RH HTTP POST Message formPortFw buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/21/2025 | SeverityHigh |
CVE-2025-4851TOTOLINK N300RH cstecgi.cgi setUploadUserData command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/18/2025 | SeverityMedium |
CVE-2025-4850TOTOLINK N300RH cstecgi.cgi setUnloadUserData command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/18/2025 | SeverityMedium |
CVE-2025-4849TOTOLINK N300RH cstecgi.cgi CloudACMunualUpdateUserdata command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/18/2025 | SeverityMedium |