CVE-2026-4497
A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Vendor
Product
CWE
Yayın Tarihi
2026-03-20 19:16:20
Güncelleme
2026-04-03 11:31:28
Source Identifier
cna@vuldb.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/hellonestor/killallbug/issues/1
https://github.com/user-attachments/files/25790616/Unauthenticated.Remote.Code.Execution.in.TOTOLINK.WA300.via.Command.Injection.in.recvUpgradeNewFw.zip
https://vuldb.com/?ctiid.352046
https://vuldb.com/?id.352046
https://vuldb.com/?submit.773875
https://www.totolink.net/