<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>N300RH 6.1c.1353_B20190305 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/n300rh-6.1c.1353_b20190305/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 26 May 2026 14:20:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/n300rh-6.1c.1353_b20190305/feed.xml" rel="self" type="application/rss+xml"/><item><title>Totolink N300RH Command Injection Vulnerability (CVE-2026-9543)</title><link>https://feed.craftedsignal.io/briefs/2026-05-totolink-rce/</link><pubDate>Tue, 26 May 2026 14:20:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-totolink-rce/</guid><description>Totolink N300RH version 6.1c.1353_B20190305 is vulnerable to remote command injection via manipulation of the 'admpass' argument in the setPasswordCfg function of the /cgi-bin/cstecgi.cgi file within the Web Management Interface, allowing for remote code execution.</description><content:encoded><![CDATA[<p>A critical vulnerability, CVE-2026-9543, has been identified in Totolink N300RH router firmware version 6.1c.1353_B20190305. The vulnerability resides within the Web Management Interface, specifically in the <code>/cgi-bin/cstecgi.cgi</code> file&rsquo;s <code>setPasswordCfg</code> function. By manipulating the <code>admpass</code> argument, a remote attacker can inject arbitrary operating system commands. Publicly available exploit code exists, increasing the risk of exploitation. This vulnerability allows unauthenticated attackers to execute commands on the underlying operating system of the router.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An unauthenticated attacker identifies a vulnerable Totolink N300RH router running firmware version 6.1c.1353_B20190305.</li>
<li>The attacker crafts a malicious HTTP request targeting the <code>/cgi-bin/cstecgi.cgi</code> endpoint.</li>
<li>Within the HTTP request, the attacker manipulates the <code>admpass</code> argument in the <code>setPasswordCfg</code> function to include OS command injection payloads.</li>
<li>The web server processes the request and passes the <code>admpass</code> argument to the underlying system.</li>
<li>The injected OS commands are executed with the privileges of the web server process.</li>
<li>The attacker can then execute commands to gain shell access, modify router configurations, or install malware.</li>
<li>The attacker uses the gained access to pivot to other devices on the network or to maintain persistence on the router.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-9543 allows an unauthenticated remote attacker to execute arbitrary operating system commands on the affected Totolink N300RH device. This can lead to complete compromise of the device, potentially enabling attackers to eavesdrop on network traffic, modify router settings, or use the device as a point of entry for further attacks on the internal network. Given the high CVSS score (9.8), this vulnerability poses a significant risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the Sigma rule to detect command injection attempts targeting the <code>/cgi-bin/cstecgi.cgi</code> endpoint (see rule <code>Detect CVE-2026-9543 Exploitation -- Command Injection in Totolink N300RH</code>).</li>
<li>Monitor web server logs for requests containing shell metacharacters in the <code>admpass</code> parameter (see rule <code>Detect CVE-2026-9543 Exploitation -- Shell Metacharacters in admpass Parameter</code>).</li>
<li>Apply any available firmware updates released by Totolink to address this vulnerability.</li>
<li>If firmware updates are not available, consider disabling remote access to the router&rsquo;s web management interface or implementing access control lists to restrict access to trusted IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve</category><category>command injection</category><category>rce</category><category>totolink</category></item></channel></rss>