CVE-2026-7633 Details
Description
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used.
A vulnerability exists in the Totolink N300RH wireless router, specifically in version 6.1c.1353_B20190305. The issue arises in the web management interface within the 'setUploadSetting' function of the 'cstecgi.cgi' file. This vulnerability allows for external control of file names, enabling remote attackers to manipulate the 'FileName' parameter and execute arbitrary file deletions on the device's filesystem with root privileges. The vulnerability is publicly exploitable, with available proof-of-concept exploitation.
Users are advised to validate and sanitize file paths, ensuring that only expected patterns are accepted and rejecting path traversal sequences. Implement authentication and authorization for sensitive endpoints, and run the web server with minimal privileges to limit the impact of such vulnerabilities.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 2, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xyh4ck/iot_poc/tree/main/TOTOLINK/N300RHv4/03_setUploadSetting_ECFNP | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/submit/806597 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360579 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/360579/cti | [email protected] | AdvisoryPermission Required |
| https://www.totolink.net/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TOTOLINK N300RH | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 2, 2026 | New CVE Received | [email protected] |
Volerion