


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in Totolink N300RT 3.4.0-B20250430. This affects an unknown function of the file /boafrm/formIpQoS. Executing a manipulation of the argume…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 05:01:43
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A buffer overflow vulnerability has been discovered in Totolink N300RT version 3.4.0-B20250430. The flaw affects an unknown function in the /boafrm/formIpQoS file through manipulation of the entry_name argument. The vulnerability can be exploited remotely and a public exploit is available. This represents a significant security risk for affected router devices as attackers can potentially execute arbitrary code remotely.
Technical details
Mitigation steps:
Affected products:
Totolink N300RT
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7219
https://github.com/xiaohaiyang-ai/IoT-Vulnerability-Research/tree/main/Vendors/TOTOLINK/N300RT/formIpQoS-Bof
https://vuldb.com/submit/808194
https://vuldb.com/vuln/359819
https://vuldb.com/vuln/359819/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
