Impact
The vulnerability resides in the ToToLink A3300R firmware and permits an attacker to inject arbitrary shell commands through the pppoeServiceName parameter sent to /cgi-bin/cstecgi.cgi. This flaw is a classic command‑injection weakness (CWE‑77). If exploited, the attacker would gain the ability to run arbitrary system commands on the device, potentially compromising the device’s confidentiality, integrity, and availability, and providing a foothold for further attacks on adjacent network equipment.
Affected Systems
ToToLink A3300R routers running firmware version 17.0.0cu.557_B20221024 are affected. The vulnerability is tied to the web‑based cstecgi.cgi CGI endpoint exposed on the device. No other ToToLink firmware versions are known to be impacted from the data given.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity. The EPSS score of less than 1% suggests that, as of the last assessment, the probability of exploitation in the wild is low, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is a remote HTTP request targeting the device’s public interface, with the attacker controlling the pppoeServiceName value to steer command execution. The prerequisite is that the attacker can reach the device over the network, and no special privileges are required to send the request.
OpenCVE Enrichment