Impact
The vulnerability permits an attacker to execute arbitrary shell commands through the recHour parameter in the /cgi-bin/cstecgi.cgi endpoint of the ToToLink A3300R router firmware. This is a classic command injection flaw (CWE-77). Based on the description, it is inferred that such exploitation could lead to the execution of arbitrary commands that compromise the device’s confidentiality, integrity, or availability.
Affected Systems
ToToLink A3300R routers running firmware version 17.0.0cu.557_B20221024 are vulnerable. The recHour parameter is exposed via the web interface’s CGI endpoint.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% signals a low probability of exploitation, and the vulnerability does not appear in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is through the web‑based management interface, requiring an HTTP request that manipulates the recHour parameter.
OpenCVE Enrichment