CVE-2026-4976
HIGHCVSS 8.8/10EPSS 0.66%
Last modified
CVE-2026-4976 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Totolink | Lr350 Firmware | 9.3.5u.6369_b20220309 |
References
- https://vuldb.com/?ctiid.353863Permissions Required, VDB Entry
- https://vuldb.com/?id.353863Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.778274Third Party Advisory, VDB Entry
- https://www.totolink.net/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-4976?
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
How severe is CVE-2026-4976?
CVE-2026-4976 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.66% probability of exploitation in the next 30 days.
How do I fix CVE-2026-4976?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49753Inconsistent Interpretation of HTTP Requests ('HTTP Request/…6.3
- CVE-2026-49754Allocation of Resources Without Limits or Throttling vulnera…8.2
- CVE-2026-49755Improper Handling of Highly Compressed Data (Data Amplificat…7.5
- CVE-2026-49756Improper Neutralization of CRLF Sequences ('CRLF Injection')…3.7
- CVE-2026-49757Authentication Bypass by Spoofing vulnerability in team-alem…9.2
- CVE-2026-49759Stack-based Buffer Overflow vulnerability in Erlang OTP erts…8.2
- CVE-2026-49760Stack-based Buffer Overflow vulnerability in Erlang OTP (erl…5.5
- CVE-2026-49762Uncontrolled Resource Consumption vulnerability in the Elixi…5.1
- CVE-2026-49763Unauthenticated PHP Object Injection in Integration for Cont…9.8
- CVE-2026-49764Unauthenticated Broken Authentication in RegistrationMagic <…9.8
- CVE-2026-49765Unauthenticated PHP Object Injection in Integration for Mail…9.8
- CVE-2026-49766Subscriber Arbitrary File Deletion in WP User Manager <= 2.9…9.9
Are you affected by CVE-2026-4976?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
