CVE-2026-7218

A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component libapmib.so. Performing a manipulation of the argument localPin results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Configurations

No configuration.

History

28 Apr 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 03:16

Updated : 2026-04-28 20:24


NVD link : CVE-2026-7218

Mitre link : CVE-2026-7218

CVE.ORG link : CVE-2026-7218


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')