Description
A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component libapmib.so. Performing a manipulation of the argument localPin results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-04-27: | Advisory disclosed |
| 2026-04-27: | VulDB entry created |
| 2026-04-27: | VulDB entry last update |
Credits
xyhackr (VulDB User)
References
vuldb.com/vuln/359818 (VDB-359818 | Totolink N300RT libapmib.so formWsc is_cmd_string_valid buffer overflow)
vuldb.com/vuln/359818/cti (VDB-359818 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/802127 (Submit #802127 | Totolink N300RT Router V3.4.0-B20250430 Buffer Overflow)
github.com/xiaohaiyang-ai/TOTOLINK-N300RT-Buffer-Overflow
www.totolink.net/
