Impact
The flaw is a command injection vulnerability that allows attackers to execute arbitrary commands on the device by manipulating the URL parameter sent to /cgi-bin/cstecgi.cgi. Attackers could gain full system control, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Totolink A3300R routers running firmware version 17.0.0cu.557_B20221024. No other affected product versions are listed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. The EPSS score of <1% suggests a low probability that the vulnerability will be exploited today, and it is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote over the web interface, where an attacker could craft a malicious URL and send it to the vulnerable /cgi-bin/cstecgi.cgi without authentication if the router permits unauthenticated or easily brute‑forced access.
OpenCVE Enrichment