Impact
A command injection flaw exists in the setSmartQosCfg function of the cstecgi.cgi component on the Totolink A3300R router. By manipulating the qos_up_bw parameter, an attacker can inject and execute arbitrary operating‑system commands on the device. This capability enables full compromise of the router, allowing control over network traffic, data, and potentially remote access to the internal network.
Affected Systems
The vulnerability affects Totolink A3300R routers running firmware version 17.0.0cu.557_b20221024. Only devices with this specific firmware build are impacted; newer or older firmware may not be susceptible.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate severity level. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. An attacker who can reach the router’s web interface can trigger the exploit remotely, as a public exploit has already been released. Because the vulnerability is command injection, successful exploitation would grant unrestricted control over the device.
OpenCVE Enrichment