Impact
The flaw allows arbitrary command execution through the stunEnable parameter exposed in /cgi-bin/cstecgi.cgi. This is a classic command-injection vulnerability (CWE‑77). An attacker who can reach the affected endpoint can run arbitrary system commands on the router, compromising confidentiality, integrity, and availability of the device and any connected networks.
Affected Systems
Totolink A3300R router, firmware version 17.0.0cu.557_B20221024.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, yet the EPSS score of less than 1% suggests low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers would need remote access to the web interface exposing /cgi-bin/cstecgi.cgi to exploit the flaw.
OpenCVE Enrichment