CVE-2026-4976 describes a critical buffer overflow vulnerability affecting the Totolink LR350 router, specifically firmware version 9.3.5u.6369_B20220309, within the setWiFiGuestCfg function of the /cgi-bin/cstecgi.cgi file. Rated 8.8 HIGH on the CVSS scale, this flaw allows a remote attacker with low privileges to achieve high impact on confidentiality, integrity, and availability due to its network attack vector and low attack complexity. An exploit for this vulnerability has been publicly disclosed, though it is not currently listed in CISA's KEV catalog or major exploit frameworks, and its low EPSS score suggests a minimal probability of active exploitation despite some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.3.5u.6369_b20220309CPE matchmatch criteria | cpe:2.3:o:totolink:lr350_firmware:9.3.5u.6369_b20220309:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.