CVE-2026-7633

A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used.
Configurations

No configuration.

History

02 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-02 15:16

Updated : 2026-05-05 19:15


NVD link : CVE-2026-7633

Mitre link : CVE-2026-7633

CVE.ORG link : CVE-2026-7633


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path