📦 Lr350 Firmware

by Totolink

🔍 What is Lr350 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-35387

CRITICAL CVSS 9.8 May 24, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK LR350 routers by exploiting a stack overflow in the loginAuth function via the http_host parameter. Attackers can gain ...

CVE-2024-35099

CRITICAL CVSS 9.8 May 14, 2024

This vulnerability is a stack overflow in the TOTOLINK LR350 router's loginAuth function, allowing remote attackers to execute arbitrary code by sending a specially crafted password parameter. It affe...

CVE-2023-37146

CRITICAL CVSS 9.8 Jul 7, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK LR350 routers by injecting malicious commands into the FileName parameter during firmware upload. Attackers can gai...

CVE-2023-37149

CRITICAL CVSS 9.8 Jul 7, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK LR350 routers by injecting malicious commands into the FileName parameter. Attackers can gain full control of affec...

CVE-2026-1158

HIGH CVSS 8.8 Jan 19, 2026

A remote buffer overflow vulnerability in Totolink LR350 routers allows attackers to execute arbitrary code by sending specially crafted POST requests to the setWizardCfg function. This affects Totoli...

CVE-2026-1157

HIGH CVSS 8.8 Jan 19, 2026

A buffer overflow vulnerability in the Totolink LR350 router's WiFi configuration function allows remote attackers to execute arbitrary code. This affects users of Totolink LR350 routers with vulnerab...

CVE-2026-1156

HIGH CVSS 8.8 Jan 19, 2026

A buffer overflow vulnerability in Totolink LR350 routers allows remote attackers to execute arbitrary code by manipulating the ssid parameter in the setWiFiBasicCfg function. This affects Totolink LR...

CVE-2025-63464

HIGH CVSS 7.5 Oct 31, 2025

This CVE describes a stack overflow vulnerability in Totolink LR350 routers via the ssid parameter. Attackers can exploit this to cause Denial of Service (DoS) through crafted requests. Users of Totol...

CVE-2025-63468

HIGH CVSS 7.5 Oct 31, 2025

This CVE describes a stack overflow vulnerability in Totolink LR350 routers via the http_host parameter. Attackers can exploit this to cause Denial of Service (DoS) by sending specially crafted reques...

CVE-2025-63466

HIGH CVSS 7.5 Oct 31, 2025

This vulnerability is a stack overflow in the Totolink LR350 router's password parameter handling that allows attackers to cause Denial of Service (DoS) via crafted requests. Attackers can crash the d...

CVE-2024-10654

MEDIUM CVSS 5.3 Nov 1, 2024

This vulnerability allows remote attackers to bypass authentication on TOTOLINK LR350 routers by manipulating the authCode parameter in the /formLoginAuth.htm endpoint. Attackers can gain unauthorized...

CVE-2024-7214

MEDIUM CVSS 6.3 Jul 30, 2024

This CVE describes a critical command injection vulnerability in TOTOLINK LR350 routers. Attackers can remotely execute arbitrary commands by manipulating the hostName parameter in the setWanCfg funct...