Description
A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-03-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in Totolink A3300R firmware 17.0.0cu.557_b20221024 allows a malicious user to inject arbitrary shell commands into the setUPnPCfg function of the cstecgi.cgi script by manipulating the enable argument. This command injection flaw is described by CWE-74 and CWE‑77 and could give an attacker the ability to run commands on the device’s operating system via the web interface.

Affected Systems

The only product specifically identified as affected is the Totolink A3300R router running firmware version 17.0.0cu.557_b20221024. No other versions or builds are listed in the information provided.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while an EPSS score of <1% suggests that exploitation is currently considered unlikely to occur widely. The vulnerability is not listed in the CISA KEV catalog. Publicly available exploits demonstrate that the flaw can be leveraged remotely through the web interface; however, the description does not specify whether authentication is required. Attackers who can reach the vulnerable CGI endpoint may potentially execute arbitrary commands, leading to full system compromise or disruptive behavior.

Generated by OpenCVE AI on May 22, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that removes the vulnerable cstecgi.cgi script or incorporates input validation.
  • If an immediate firmware update is not feasible, block external access to /cgi-bin/cstecgi.cgi with firewalls or network segmentation to limit exposure to trusted internal hosts.
  • Implement a web application firewall that detects and rejects suspicious input patterns in the enable parameter.
  • Enable logging for all CGI requests and review logs regularly for signs of attempted exploitation.

Generated by OpenCVE AI on May 22, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 30 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:totolink:a3300r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:*

Mon, 30 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a3300r
Vendors & Products Totolink a3300r

Mon, 30 Mar 2026 03:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A3300R cstecgi.cgi setUPnPCfg command injection
First Time appeared Totolink
Totolink a3300r Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3300r Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3300r A3300r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-30T11:26:52.093Z

Reserved: 2026-03-29T17:50:50.164Z

Link: CVE-2026-5103

cve-icon Vulnrichment

Updated: 2026-03-30T11:25:10.179Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-30T02:16:15.840

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-5103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-22T15:30:38Z

Weaknesses