Impact
A command injection flaw exists in the setSmartQosCfg function of /cgi-bin/cstecgi.cgi. By manipulating the qos_up_bw argument, an attacker can inject and run arbitrary shell commands on the router. The vulnerability is exposed through the network, permitting attacks without local access and potentially granting full control of the device.
Affected Systems
Totolink A3300R routers running firmware version 17.0.0cu.557_b20221024 are affected. This flaw is tied to that specific firmware revision and may not impact earlier or later releases.
Risk and Exploitability
The CVSS v3 base score of 5.3 indicates moderate severity, yet the attack vector is remote, making it readily exploitable over the network. An EPSS score of 3% suggests low current exploit frequency, but the existence of a public exploit raises concern. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed large-scale attacks yet, but administrators should consider it a potential risk for unauthorized remote control.
OpenCVE Enrichment