WA300
Totolink- Software type
- —
- Catalog vulnerabilities
- 8
Severity across 8 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 8 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, WA300 has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of WA300 and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-7721Totolink WA300 cstecgi.cgi NTPSyncWithHost command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/04/2026 | SeverityMedium |
CVE-2026-7720Totolink WA300 POST Request cstecgi.cgi setLanguageCfg command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/04/2026 | SeverityMedium |
CVE-2026-7719Totolink WA300 POST Request cstecgi.cgi loginauth buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/04/2026 | SeverityCritical |
CVE-2026-7718Totolink WA300 POST Request cstecgi.cgi setWebWlanIdx command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/04/2026 | SeverityMedium |
CVE-2026-7717Totolink WA300 POST Request cstecgi.cgi UploadCustomModule buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/04/2026 | SeverityHigh |
CVE-2026-4497Totolink WA300 cstecgi.cgi recvUpgradeNewFw os command injection | Exploitation statusPublic exploit | FixYes | Published03/20/2026 | SeverityMedium |
CVE-2026-2167Totolink WA300 cstecgi.cgi setAPNetwork os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published02/08/2026 | SeverityMedium |
CVE-2026-0641TOTOLINK WA300 cstecgi.cgi sub_401510 command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/06/2026 | SeverityMedium |