Impact
The flaw lies in the setTracerouteCfg handler of /cgi-bin/cstecgi.cgi on the Totolink LR350. By manipulating the command argument in a POST request, an attacker can inject arbitrary shell commands. This leads to remote execution on the device, potentially giving full control over the router. The weakness is a command injection (CWE-74 and CWE-77).
Affected Systems
The affected device is the Totolink LR350 router running firmware version 9.3.5u.6369_B20220309. No other firmware revisions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of 2% shows a low but non‑zero probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network reachability to the router’s web interface to send a crafted POST request; no authentication or local privilege escalation is required, making remote exploitation straightforward.
OpenCVE Enrichment