Lr350 Firmware Totolink Lr350 Firmware

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Totolink Lr350 Firmware.

By the Year

In 2026 there have been 6 vulnerabilities in Totolink Lr350 Firmware with an average score of 8.0 out of ten. Lr350 Firmware did not have any published security vulnerabilities last year. That is, 6 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 6 7.97
2025 0 0.00
2024 7 9.23
2023 0 0.00
2022 11 9.25

It may take a day or so for new Lr350 Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Totolink Lr350 Firmware Security Vulnerabilities

Totolink LR350 9.3.5u Buffer Overflow via POST ssid in cstecgi.cgi
CVE-2026-1158 8.8 - High - January 19, 2026

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Classic Buffer Overflow

Totolink LR350 9.3.5u.6369 Remote Buffer Overflow in setWiFiEasyCfg
CVE-2026-1157 8.8 - High - January 19, 2026

A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Classic Buffer Overflow

Totolink LR350 9.3.5u.6369_B20220309 Buffer Overflow via setWiFiBasicCfg
CVE-2026-1156 8.8 - High - January 19, 2026

A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Classic Buffer Overflow

Totolink LR350 9.3.5u.6369 Buffer Overflow in setWiFiEasyGuestCfg (Remote)
CVE-2026-1155 8.8 - High - January 19, 2026

A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

Classic Buffer Overflow

Totolink LR350 9.3.5u Command Injection via POST setTracerouteCfg (Remote)
CVE-2026-1150 6.3 - Medium - January 19, 2026

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

Command Injection

Totolink LR350 9.3.5u remote command injection via /cgi-bin/cstecgi.cgi
CVE-2026-1149 6.3 - Medium - January 19, 2026

A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument ip leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

Command Injection

TOTOLINK LR350 <=9.3.5u.6369 auth bypass via /formLoginAuth.htm authCode=1
CVE-2024-10654 9.1 - Critical - November 01, 2024

A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.3.5u.6698_B20230810 is able to address this issue. It is recommended to upgrade the affected component.

Insecure Direct Object Reference / IDOR

Access Control Bypass in TOTOLINK LR350 V9.3.5u via /cgi-bin/ExportSettings.sh
CVE-2024-42967 9.8 - Critical - August 15, 2024

Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

Command Injection in TOTOLINK LR350 9.3.5u.6369 setWanCfg HostName
CVE-2024-7214 8.8 - High - July 30, 2024

A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272785 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Command Injection

Cmd Injection in TOTOLINK LR350 v9.3.5u via host_time
CVE-2024-36783 - June 03, 2024

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.

Stack Overflow via http_host in loginAuth on TOTOLINK LR350 v9.3.5
CVE-2024-35387 - May 24, 2024

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

TOTOLINK LR350 V9.3.5 stack overflow via loginAuth password
CVE-2024-35099 - May 14, 2024

TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

TOTOLINK LR350 V9.3.5u Stack Overflow via urldecode before fix
CVE-2024-34308 - May 14, 2024

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.

TOTOLINK LR350 V9.3 buffer overflow in setTracerouteCfg (pre-6369_B20220309)
CVE-2022-44258 8.8 - High - November 23, 2022

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.

Memory Corruption

Post-auth Buffer Overflow via pppoeUser in SetOpModeCfg on LR350 V9.3.5u
CVE-2022-44257 8.8 - High - November 23, 2022

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.

Memory Corruption

Totolink LR350 V9.3.5u.6369_B20220309 Pre-Auth Buffer Overflow in Main
CVE-2022-44255 9.8 - Critical - November 23, 2022

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.

Memory Corruption

TOTOLINK LR350 pre9.3.5u.6369 buffer overflow in setSmsCfg (postauth)
CVE-2022-44254 8.8 - High - November 23, 2022

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.

Memory Corruption

TOTOLINK LR350 V9.3.5u.6369 Post-auth Buffer Overflow via setDiagnosisCfg
CVE-2022-44253 8.8 - High - November 23, 2022

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.

Memory Corruption

Command Injection in setUploadSetting of TOTOLINK NR1800X V9.1.0u.6279_B20210910
CVE-2022-44252 9.8 - Critical - November 23, 2022

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.

Shell injection

Command Injection in TOTOLINK NR1800X 9.1.0u via ussd Parameter
CVE-2022-44251 9.8 - Critical - November 23, 2022

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

Shell injection

Command Injection via setOpModeCfg in TOTOLINK NR1800X 9.1.0u
CVE-2022-44250 9.8 - Critical - November 23, 2022

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

Shell injection

Command Injection in TOTOLINK NR1800X v9.1.0u via UploadFirmwareFile
CVE-2022-44249 9.8 - Critical - November 23, 2022

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.

Shell injection

TOTOLINK LR350 buffer overflow via setParentalRules (v9.3.5)
CVE-2022-44259 8.8 - High - November 23, 2022

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.

Memory Corruption

Totolink LR350 V9.3.5u-6369 buffer overflow in setIpPortFilterRules
CVE-2022-44260 8.8 - High - November 23, 2022

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Totolink Lr350 Firmware or by Totolink? Click the Watch button to subscribe.

Totolink
Vendor

subscribe