CVE-2026-3301Disclosure(totolink / n300rh)

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch totolink n300rh systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n300rh
  • n300rh_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Exploit: 2 classified signals
  • Peaked 1d ago at 7 mentions (2026-02-27); latest day: 1
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
n300rhn300rh_firmware

3 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-02-27: 7Mentions · 2026-03-04: 1PoC Mentioned / Linked · 2026-02-27: 2Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-27: 6Technical Details · 2026-03-04: 102-2703-04
Signal classification2 categories
Disclosure
675.0%
Exploit
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-277
Disclosure5Exploit2
2026-03-041
Disclosure1
Full discourse8 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3301 (CVSS:8.9, CRITICAL) is Analyzed. A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the functi..https://nvd.nist.gov/vuln/detail/CVE-2026-3301 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A critical vulnerability (CVE-2026-3301) was identified in Totolink N300RH firmware, with a CVSS score of 8.9, but no PoC, exploit, or patch details were provided.

    0000025
    173 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Totolink N300RH (CVE-2026-3301) https://vuldb.com/?id.348052

    Post summary

    A new vulnerability, CVE‑2026‑3301, has been disclosed for the Totolink N300RH router, noting increased severity but providing no further details.

    0000078
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3301 A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cg… https://www.cve.org/CVERecord?id=CVE-2026-3301

    Post summary

    A new vulnerability (CVE-2026-3301) was discovered in Totolink N300RH firmware affecting the setWebWlanIdx function, but no PoC, exploit, or patch details were provided.

    00000103
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-3301: CRITICAL] Security alert: Vulnerability found in Totolink N300RH router can lead to remote OS command injection through its Web Management Interface. Public exploit available. Take caution!#cve,CVE-2026-3301,#cybersecurity https://cvefind.com/CVE-2026-3301

    Post summary

    The post announces a critical CVE-2026-3301 vulnerability in Totolink routers, notes remote OS command injection via the Web Interface, and indicates a public exploit is available, but provides no patch details or evidence of active attacks.

    0000075
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-3301** is a critical remote code execution (RCE) vulnerability affecting the Totolink N300RH router, specifically firmware version 6.1c.1353_B20190305. The flaw resides in the `setWebWlanIdx` function within the `/cgi-bin/cstecgi.cgi` component of the Web Management Interface. An attacker can exploit this vulnerability by manipulating the `webWlanIdx` argument, leading to arbitrary OS command execution on the device. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #DDoS https://cvetodo.com/cve/CVE-2026-3301

    Post summary

    A critical RCE flaw in Totolink N300RH routers' web interface (setWebWlanIdx) allows attackers to execute arbitrary OS commands via the webWlanIdx parameter.

    0000044
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3301 - Critical A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component W... https://www.thehackerwire.com/vulnerability/CVE-2026-3301/ https://t.co/oQpsmtr3qg

    Post summary

    The tweet announces the discovery of CVE‑2026‑3301 in Totolink routers, naming the vulnerable function but lacking exploitation or mitigation details.

    0000061
    119 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Exploit

    🚨 CRITICAL: Totolink N300RH routers (v6.1c.1353_B20190305) hit by unauthenticated OS command injection (CVSS 9.3)! Exploit code is public — restrict access & monitor urgently. Patch ASAP when available. https://radar.offseq.com/threat/cve-2026-3301-os-command-injection-in-toto... https://t.co/7b2zTdFQmL

    Post summary

    The tweet announces a critical OS command injection vulnerability in Totolink N300RH routers, with publicly available exploit code and a CVSS of 9.3, and urges immediate patching and monitoring.

    0000048
    270 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3301 - Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection Intel Report: https://ift.tt/uJTcYwV

    Post summary

    A new OS command injection vulnerability (CVE-2026-3301) in Totolink N300RH's web management interface has been reported.

    000004
    341 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
HWtotolinkn300rh4.0--
OStotolinkn300rh_firmware6.1c.1349_b20181018--
OStotolinkn300rh_firmware6.1c.1353_b20190305--

Explore more