CVE-2026-10187
A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file w
CVSS
9.8
Critical
EPSS
7.3%
p94
KEV
—
Exploit Today
28
0-100
Published: May 31, 2026 · Last modified: Jul 22, 2026 · CWE-119 · CWE-121
1.4%EPSS · 30 days7.3%
2026-07-052026-08-01
A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10187
- vuldb.comhttps://vuldb.com/submit/819971
- vuldb.comhttps://vuldb.com/submit/820133
- vuldb.comhttps://vuldb.com/vuln/367468
- vuldb.comhttps://vuldb.com/vuln/367468/cti
- www.totolink.nethttps://www.totolink.net/
- wx.mail.qq.comhttps://wx.mail.qq.com/s?k=iXbjuHnfMwoD0oWW3v
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-678229.8 CRI21.8%
——7Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.3dCVE-2026-157227.5 HIG40.7%
——12A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.3dCVE-2026-438327.5 HIG15.8%
——5Full details and mitigation steps are currently restricted and will be published at a later date.3dCVE-2026-438317.5 HIG15.8%
——5Full details and mitigation steps are currently restricted and will be published at a later date.3dCVE-2026-438297.5 HIG15.8%
——5Full details and mitigation steps are currently restricted and will be published at a later date.3dCVE-2026-105358.4 HIG2.3%
——1IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.3d