Description
A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-03-30
Score: 5.3 Medium
EPSS: 2.7% Low
KEV: No
Impact: Remote Command Execution
Action: Patch Now
AI Analysis

Impact

A command injection flaw exists in the setSmartQosCfg function of /cgi-bin/cstecgi.cgi. By manipulating the qos_up_bw argument, an attacker can inject and run arbitrary shell commands on the router. The vulnerability is exposed through the network, permitting attacks without local access and potentially granting full control of the device.

Affected Systems

Totolink A3300R routers running firmware version 17.0.0cu.557_b20221024 are affected. This flaw is tied to that specific firmware revision and may not impact earlier or later releases.

Risk and Exploitability

The CVSS v3 base score of 5.3 indicates moderate severity, yet the attack vector is remote, making it readily exploitable over the network. An EPSS score of 3% suggests low current exploit frequency, but the existence of a public exploit raises concern. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed large-scale attacks yet, but administrators should consider it a potential risk for unauthorized remote control.

Generated by OpenCVE AI on March 30, 2026 at 17:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that fixes the setSmartQosCfg command injection.
  • Verify that the device firmware has been successfully upgraded to a version that resolves the flaw.
  • Restrict or disable remote web management if the router does not need it, and limit access to the management interface to trusted internal networks.
  • Configure firewall rules to block or monitor traffic to /cgi-bin/cstecgi.cgi until a patch is available.

Generated by OpenCVE AI on March 30, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 30 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:totolink:a3300r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:*

Mon, 30 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a3300r
Vendors & Products Totolink a3300r

Mon, 30 Mar 2026 03:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Title Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection
First Time appeared Totolink
Totolink a3300r Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3300r Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3300r A3300r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-30T15:56:03.600Z

Reserved: 2026-03-29T17:50:47.089Z

Link: CVE-2026-5102

cve-icon Vulnrichment

Updated: 2026-03-30T15:55:55.316Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-30T00:16:01.997

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-5102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T20:56:12Z

Weaknesses