CVE-2026-10187: Totolink n300rh

Critical severity, CVSS 9.8. EPSS: 7.3% chance of exploitation in the next 30 days.

A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Affected products

  • Totolink n300rh: version 6.1c.1353_B20190305 only

Published 2026-05-31. Last modified 2026-07-22.