Impact
An OS command injection flaw exists in Totolink A3300R firmware through the stunServerAddr parameter in /cgi-bin/cstecgi.cgi, allowing a remote attacker to execute arbitrary commands. This flaw, classified as CWE‑78, can compromise confidentiality, integrity, and availability of affected devices because code runs with the device’s privileges. Based on the description, it is inferred that exploitation would compromise those aspects.
Affected Systems
The vulnerability is present in Totolink A3300R routers running firmware version 17.0.0cu.557_B20221024. No other versions are reported affected. The affected product is the Totolink A3300R, a home‑network router.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of <1% suggests low current exploitation probability, yet the existence of a remote command execution avenue makes it highly damaging if exploited. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker sending a crafted HTTP request with a malicious stunServerAddr value to the router.
OpenCVE Enrichment