Impact
The flaw lies in the setWebWlanIdx argument of /cgi-bin/cstecgi.cgi, a component of the router’s web management interface. An attacker can alter this parameter to inject arbitrary operating‑system commands that the device executes with elevated privileges. The attack does not require local access; it can be triggered remotely by sending a malicious HTTP request. This results in full compromise of the router, enabling the attacker to run any command, modify firmware, or use the device as a pivot point for further attacks. The weakness is an OS command injection, categorized as CWE‑77 and CWE‑78.
Affected Systems
Only the Totolink N300RH model running firmware version 6.1c.1353_B20190305 is explicitly listed as vulnerable. Based on the description, it is unclear whether earlier firmware releases contain the same flaw; the vulnerability is documented solely for this revision.
Risk and Exploitability
The CVSS score of 9.3 marks the issue as critical, emphasizing the remote execution capability with full device privileges. An EPSS score of 4% indicates a moderate likelihood of exploitation in the wild, especially after the release of public proof‑of‑concept code. The vulnerability is not yet in the CISA KEV catalog, but its remote nature and lack of built‑in mitigation suggest a high priority for immediate action to prevent compromise.
OpenCVE Enrichment