CVE-2026-7747Disclosure

HIGHCVSS 8.9 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument Password results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-04); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-05-03: 1Mentions · 2026-05-04: 4Mentions · 2026-05-11: 1Mentions · 2026-05-15: 2Mentions · 2026-05-24: 1PoC Mentioned / Linked · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-24: 1Exploit Tool / Code · 2026-05-15: 1Active Exploitation · 2026-05-11: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-05-04: 4Technical Details · 2026-05-15: 2Technical Details · 2026-05-24: 105-0305-0405-1105-1505-24
Signal classification4 categories
Disclosure
444.4%
Patch
333.3%
Active Exploitation
111.1%
General
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-031
Disclosure1
2026-05-044
Disclosure3Patch1
2026-05-111
Active Exploitation1
2026-05-152
General1Patch1
2026-05-241
Patch1
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    Patch

    https://lyrie.ai/research/research/cve-2026-7747-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked advisory discusses CVE‑2026‑7747, providing technical details, exploit code, and a patch for the vulnerability, but there is no evidence of active exploitation.

    0001026
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-7747 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post merely announces a CVE identifier with its CVSS score and severity rating, without any additional technical or operational context.

    1000045
    215 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7747 A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the… https://www.cve.org/CVERecord?id=CVE-2026-7747

    Post summary

    The text announces CVE‑2026‑7747, a security flaw in a Totolink router’s loginauth function, but provides no PoC, exploit, or mitigation details.

    00010233
    57.4K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7747 — CVSS 9.8/10 ██████████ A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/gUjenetAoi

    Post summary

    The tweet announces CVE‑2026‑7747 as a critical flaw in Totolink N300RH, provides its CVSS score, and urges users to apply the available patch.

    1000050
    26 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Totolink N300RH (CVE-2026-7747) https://vuldb.com/vuln/360922

    Post summary

    The post announces a newly disclosed vulnerability (CVE‑2026‑7747) for Totolink N300RH, noting an increased severity but without further technical or incident details.

    0001073
    2.1K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-7747 (CVSS 9.8) - Remote buffer overflow in Totolink N300RH router v3.2.4. Exploit publicly available. Affects loginauth function in /cgi-bin/cstecgi[.]cgi. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/vShFkkKnON

    Post summary

    The post announces a critical CVE-2026-7747 remote buffer overflow in Totolink N300RH routers, notes the exploit is publicly available, and urges an immediate patch.

    0000082
    30 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting Totolink N300RH (CVE-2026-7747) https://vuldb.com/vuln/360922/cti

    Post summary

    Elevated activity against Totolink N300RH indicates the CVE-2026-7747 may be under active exploitation, though specific details or patches are not provided.

    0000074
    2.2K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Totolink N300RH Password buffer overflow vulnerability (CVE-2026-7747) #CVE20267747 #CyberSecurity #PasswordBufferOverflowVulnerability #Totolink https://www.systemtek.co.uk/?p=50892 https://t.co/2Ht9WaWLNH

    Post summary

    The tweet announces a new password buffer overflow vulnerability in Totolink N300RH (CVE‑2026‑7747) but provides no exploit, mitigation, or in‑the‑wild activity details.

    0000045
    1.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7747 A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the… https://www.cve.org/CVERecord?id=CVE-2026-7747 ----- Traducción: CVE-2026-7747 Se … http://infoflow.cloud`

    Post summary

    CVE‑2026‑7747 is a newly discovered vulnerability affecting the loginauth function in /cgi-bin/cstecgi.cgi on Totolink N300RH firmware 3.2.4‑B20220812; no exploit, patch, or active exploitation is mentioned.

    0000037
    75 followersView on X

Explore more