CVE-2026-7218 Details
Description
A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component libapmib.so. Performing a manipulation of the argument localPin results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
A stack-based buffer overflow vulnerability has been identified in the Totolink N300RT router, specifically in the boa web server, within the function 'is_cmd_string_valid' of the component 'libapmib.so'. This vulnerability exists in routers running firmware version 3.4.0-B20250430 or earlier. The issue arises because the function fails to properly validate the length of the 'localPin' parameter in the '/boafrm/formWsc' endpoint. An authenticated attacker can exploit this vulnerability by sending a crafted POST request with an oversized payload, bypassing Cross-Site Request Forgery (CSRF) and token checks. This exploitation can lead to a Denial of Service (DoS) condition or potentially allow for Remote Code Execution (RCE).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 28, 2026CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xiaohaiyang-ai/TOTOLINK-N300RT-Buffer-Overflow | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/submit/802127 | [email protected] | Technical Description |
| https://vuldb.com/vuln/359818 | [email protected] | AdvisoryExploit |
| https://vuldb.com/vuln/359818/cti | [email protected] | Content Wall |
| https://www.totolink.net/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TOTOLINK N300RT | <= 3.4.0-B20250430 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | New CVE Received | [email protected] |
Volerion