Description
A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument pptpPassThru results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Published: 2026-03-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the setVpnPassCfg function of the /cgi-bin/cstecgi.cgi component that handles the pptpPassThru parameter. An attacker who can supply a crafted value can inject arbitrary operating‑system commands that are subsequently executed by the router. This vulnerability satisfies both command injection and operating‑system command injection weakness classes, allowing the attacker to run code with the privileges of the web server process and potentially compromise the device and the internal network.

Affected Systems

The affected product is the Totolink A3300R router running firmware version 17.0.0cu.557_b20221024. No other products or firmware revisions are listed in the advisory.

Risk and Exploitability

The CVSS base score is 5.3, indicating moderate severity, and the EPSS score of <1 % suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The advisory states that the attack can be initiated remotely, but it does not clarify whether authentication or administrative privileges are required; it is therefore inferred that access to the router’s web interface may be necessary. Once reached, a crafted HTTP request carrying a malicious pptpPassThru value can trigger the injection with no further conditions noted.

Generated by OpenCVE AI on May 22, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router with the latest firmware that addresses the command injection flaw.
  • If a patch is not available, disable the PPTP Pass‑Thru feature through the web interface to remove the vulnerable code path.
  • Restrict access to the router’s web‑based management interface to trusted IP addresses or the local network only.
  • Monitor web‑interface logs for abnormal use of the cstecgi.cgi endpoint and investigate any suspicious parameters.
  • Configure perimeter firewall or NAT rules to block external connections to the router’s management ports.

Generated by OpenCVE AI on May 22, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 30 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:totolink:a3300r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:*

Mon, 30 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a3300r
Vendors & Products Totolink a3300r

Mon, 30 Mar 2026 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument pptpPassThru results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Title Totolink A3300R Parameter cstecgi.cgi setVpnPassCfg command injection
First Time appeared Totolink
Totolink a3300r Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3300r Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3300r A3300r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-30T13:58:27.213Z

Reserved: 2026-03-29T17:50:56.050Z

Link: CVE-2026-5105

cve-icon Vulnrichment

Updated: 2026-03-30T13:58:21.503Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-30T04:16:09.680

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-5105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-22T15:30:38Z

Weaknesses