Impact
A weakness in Totolink A3300R firmware 17.0.0cu.557_b20221024 allows a malicious user to inject arbitrary shell commands into the setUPnPCfg function of the cstecgi.cgi script by manipulating the enable argument. This command injection flaw is described by CWE-74 and CWE‑77 and could give an attacker the ability to run commands on the device’s operating system via the web interface.
Affected Systems
The only product specifically identified as affected is the Totolink A3300R router running firmware version 17.0.0cu.557_b20221024. No other versions or builds are listed in the information provided.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while an EPSS score of <1% suggests that exploitation is currently considered unlikely to occur widely. The vulnerability is not listed in the CISA KEV catalog. Publicly available exploits demonstrate that the flaw can be leveraged remotely through the web interface; however, the description does not specify whether authentication is required. Attackers who can reach the vulnerable CGI endpoint may potentially execute arbitrary commands, leading to full system compromise or disruptive behavior.
OpenCVE Enrichment