Description
A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-03-30
Score: 5.3 Medium
EPSS: 2.9% Low
KEV: No
Impact: Remote code execution
Action: Apply Patch
AI Analysis

Impact

A command injection flaw exists in the setSmartQosCfg function of the cstecgi.cgi component on the Totolink A3300R router. By manipulating the qos_up_bw parameter, an attacker can inject and execute arbitrary operating‑system commands on the device. This capability enables full compromise of the router, allowing control over network traffic, data, and potentially remote access to the internal network.

Affected Systems

The vulnerability affects Totolink A3300R routers running firmware version 17.0.0cu.557_b20221024. Only devices with this specific firmware build are impacted; newer or older firmware may not be susceptible.

Risk and Exploitability

The CVSS base score is 5.3, indicating a moderate severity level. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. An attacker who can reach the router’s web interface can trigger the exploit remotely, as a public exploit has already been released. Because the vulnerability is command injection, successful exploitation would grant unrestricted control over the device.

Generated by OpenCVE AI on March 30, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Totolink website for an updated firmware release that addresses this flaw.
  • Install the latest firmware on all affected routers promptly.
  • If a patch is not available, restrict external access to the router’s web interface or block the /cgi-bin/cstecgi.cgi endpoint to prevent remote manipulation.
  • Apply network segmentation to isolate the router from critical internal assets.
  • Monitor router logs for unusual command execution attempts and investigate promptly.

Generated by OpenCVE AI on March 30, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 30 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:totolink:a3300r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:*

Mon, 30 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a3300r
Vendors & Products Totolink a3300r

Mon, 30 Mar 2026 03:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Title Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection
First Time appeared Totolink
Totolink a3300r Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3300r Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3300r A3300r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-30T15:56:03.600Z

Reserved: 2026-03-29T17:50:47.089Z

Link: CVE-2026-5102

cve-icon Vulnrichment

Updated: 2026-03-30T15:55:55.316Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-30T00:16:01.997

Modified: 2026-03-30T15:49:31.493

Link: CVE-2026-5102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T07:03:48Z

Weaknesses