Ghostwire

CVE-2026-6158: A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file...

HIGH CVSS 7.5 EPSS 2.37%

Published: April 13, 2026 | Last Modified: April 14, 2026

Description

A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Moderate — 2.37% (85th percentile)

Measurable exploitation probability. Should be patched in the normal vulnerability management cycle.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References