CVE-2026-7218

A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component libapmib.so. Performing a manipulation of the argument localPin results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Configurations

No configuration.

History

24 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue detectada en Totolink N300RT 3.4.0-B20250430. El elemento afectado es la función is_cmd_string_valid del archivo /boafrm/formWsc del componente libapmib.so. Realizar una manipulación del argumento localPin resulta en un desbordamiento de búfer. El ataque es posible de llevar a cabo de forma remota. El exploit ya es público y puede ser utilizado.

28 Apr 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 03:16

Updated : 2026-07-24 08:10


NVD link : CVE-2026-7218

Mitre link : CVE-2026-7218

CVE.ORG link : CVE-2026-7218


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')