Impact
An issue in Totolink A3300R firmware allows attackers to execute arbitrary commands via the stunMinAlive parameter exposed in /cgi-bin/cstecgi.cgi. This flaw represents a command injection vulnerability (CWE‑78) that can lead to full control over the affected device, compromising confidentiality, integrity, and availability of the network it serves.
Affected Systems
The vulnerability affects Totolink routers running A3300R firmware version 17.0.0cu.557_B20221024. The affected CPEs indicate a hardware device and its associated firmware, so any units deployed with that build are susceptible.
Risk and Exploitability
The CVSS score of 9.8 marks it a critical vulnerability, while an EPSS score of less than 1% suggests a low probability of exploitation at the present time. The flaw is not listed in the CISA KEV catalog. The likely attack vector is network-based, requiring an attacker to send a specially crafted HTTP request to the device’s web interface; no authentication prerequisites are reported, so the attack could be performed against any device exposed to the network.
OpenCVE Enrichment