๐Ÿ” CVE Alert

CVE-2026-7218

HIGH 7.2

Totolink N300RT libapmib.so formWsc is_cmd_string_valid buffer overflow

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component libapmib.so. Performing a manipulation of the argument localPin results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CWE CWE-120 CWE-119
Vendor totolink
Product n300rt
Published Apr 28, 2026
Stay Ahead of the Next One

Get instant alerts for totolink n300rt

Be the first to know when new high vulnerabilities affecting totolink n300rt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Totolink / N300RT
3.4.0-B20250430

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/359818 vuldb.com: https://vuldb.com/vuln/359818/cti vuldb.com: https://vuldb.com/submit/802127 github.com: https://github.com/xiaohaiyang-ai/TOTOLINK-N300RT-Buffer-Overflow totolink.net: https://www.totolink.net/

Credits

๐Ÿ” xyhackr (VulDB User)