Impact
A remote attacker can manipulate the ip argument in a POST request to /cgi-bin/cstecgi.cgi’s setDiagnosisCfg function on the Totolink LR350 router. The flaw allows the execution of arbitrary shell commands on the device, compromising confidentiality, integrity, and availability. The vulnerability maps to path and command injection weaknesses (CWE‑74, CWE‑77).
Affected Systems
Products affected are Totolink LR350 routers running firmware version 9.3.5u.6369_B20220309. No other vendor or product versions are listed as affected at this time.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. An EPSS score of 2% suggests industrial exploitation is possible but unlikely, and the vulnerability is not yet included in CISA’s KEV list. Attackers can trigger the flaw remotely via HTTP POST to the router’s exposed interface. Public exploits are available, so the risk is real. The flaw appears exploitable without authentication according to the description, but the exact authentication requirements are not specified, so that detail is inferred as potentially unauthenticated.
OpenCVE Enrichment