Impact
An attacker can send a specially crafted password value to /cgi-bin/cstecgi.cgi on a ToToLink A3300R router, enabling execution of arbitrary shell commands on the device. The flaw arises from unsanitized input being passed to the underlying system shell via the password parameter, allowing malicious actors to gain remote code execution capability, install backdoors, exfiltrate data, or disrupt network services.
Affected Systems
The affected item is a ToToLink A3300R router running firmware version 17.0.0cu.557_B20221024. Earlier or later firmware versions may not contain the flaw if the command injection vector has been removed.
Risk and Exploitability
The CVSS score of 6.5 reflects a medium severity risk, while the EPSS score of under 1 percent indicates a low probability of current exploitation in the wild. Because the flaw is not listed in the CISA KEV catalog, it has not yet been observed in known exploits. An attacker would likely reach the device remotely over the local network, submitting a password with injected commands to trigger code execution. Mitigations that prevent unauthorized network access can reduce the attack surface.
OpenCVE Enrichment