Description
A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-01-19
Score: 5.3 Medium
EPSS: 1.8% Low
KEV: No
Impact: Remote Command Execution
Action: Apply Patch
AI Analysis

Impact

The flaw lies in the setTracerouteCfg handler of /cgi-bin/cstecgi.cgi on the Totolink LR350. By manipulating the command argument in a POST request, an attacker can inject arbitrary shell commands. This leads to remote execution on the device, potentially giving full control over the router. The weakness is a command injection (CWE-74 and CWE-77).

Affected Systems

The affected device is the Totolink LR350 router running firmware version 9.3.5u.6369_B20220309. No other firmware revisions are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of 2% shows a low but non‑zero probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network reachability to the router’s web interface to send a crafted POST request; no authentication or local privilege escalation is required, making remote exploitation straightforward.

Generated by OpenCVE AI on April 18, 2026 at 15:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that fixes the setTracerouteCfg command injection flaw.
  • Restrict or disable remote access to the router’s management interface so that only trusted networks can reach it.
  • Configure firewall or ACL rules to block unsolicited POST traffic to /cgi-bin/cstecgi.cgi until a patch is applied.

Generated by OpenCVE AI on April 18, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:totolink:lr350_firmware:*:*:*:*:*:*:*:*

Thu, 29 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink lr350 Firmware
CPEs cpe:2.3:h:totolink:lr350:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:lr350_firmware:9.3.5u.6369_b20220309:*:*:*:*:*:*:*
Vendors & Products Totolink lr350 Firmware

Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink lr350
Vendors & Products Totolink
Totolink lr350

Mon, 19 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Title Totolink LR350 POST Request cstecgi.cgi setTracerouteCfg command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink Lr350 Lr350 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:45:01.041Z

Reserved: 2026-01-18T13:55:32.781Z

Link: CVE-2026-1150

cve-icon Vulnrichment

Updated: 2026-01-20T21:27:50.275Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-19T11:15:49.250

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-1150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T16:00:04Z

Weaknesses