


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the com…
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 04:01:34
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A buffer overflow vulnerability (CVE-2026-7218) has been discovered in Totolink N300RT router version 3.4.0-B20250430. The vulnerability exists in the is_cmd_string_valid function within the /boafrm/formWsc file of the libapmib.so component. Attackers can exploit this by manipulating the localPin argument, resulting in a buffer overflow condition. The vulnerability can be exploited remotely, making it particularly dangerous. A public exploit is now available, increasing the risk of active exploitation. The affected router model is commonly used in home and small business environments.
Technical details
Mitigation steps:
Affected products:
Totolink N300RT
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7218
https://github.com/xiaohaiyang-ai/TOTOLINK-N300RT-Buffer-Overflow
https://vuldb.com/submit/802127
https://vuldb.com/vuln/359818
https://vuldb.com/vuln/359818/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
