CVE-2026-1157Active Exploitation(totolink / lr350)

HIGHCVSS 7.4 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for totolink lr350 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lr350
  • lr350_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
lr350lr350_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-09: 1Exploit Tool / Code · 2026-04-09: 1Active Exploitation · 2026-04-09: 104-09
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TOTOLINK routers (CVE-2026-1157) 2026-04-09 20:17:31 UTC Source IP: 176.65.139.60 🇩🇪 POST /cgi-bin/cstecgi.cgi IOCs: 103.130.214.71 🇻🇳 hxxp://103.130.214.71:1212/cat.sh 56c7916816349aebe450a16257b8448c https://t.co/uWLpPZaZUg

    Post summary

    The post documents an active remote code execution attempt against TOTOLINK routers, referencing a linked script that likely serves as a PoC/exploit, with no patch or mitigation information provided.

    02052566
    1.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtotolinklr350---
OStotolinklr350_firmware9.3.5u.6369_b20220309--

Explore more