Impact
This vulnerability arises from improper handling of the week parameter in the cgi script, enabling attackers to inject and execute arbitrary system commands. This flaw permits unauthorized command execution, potentially compromising the device, data, and network integrity. The weakness is a command injection flaw classified as CWE-77.
Affected Systems
The vulnerable firmware is ToToLink A3300R, version 17.0.0cu.557_B20221024. Devices running this firmware are susceptible; other firmware revisions are not referenced.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity risk, while the EPSS score of less than 1% suggests low current exploitation likelihood. It is not listed in the CISA KEV catalog. The vulnerability can be triggered via HTTP requests to /cgi-bin/cstecgi.cgi supplying a crafted week parameter, making it a remote attack vector that does not require privileged local access. The impact is full command execution under the web service's privileges, potentially escalating to full device compromise.
OpenCVE Enrichment