Description
A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument pptpPassThru results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Published: 2026-03-30
Score: 5.3 Medium
EPSS: 3.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The setVpnPassCfg function within cstecgi.cgi processes the pptpPassThru argument without adequate validation, allowing an attacker to embed arbitrary operating‑system commands in that parameter. When the router receives such a crafted value, the commands execute with the privileges of the web server process, effectively granting remote command execution. This weakness permits an attacker to compromise the device, exfiltrate data, or pivot to the internal network.

Affected Systems

The flaw affects all Totolink A3300R routers running firmware 17.0.0cu.557_b20221024. No other firmware versions or models are listed in the advisory.

Risk and Exploitability

With a CVSS base score of 5.3 the vulnerability is rated moderate, and an EPSS score of 4% indicates a relatively low exploitation likelihood in the wild. The advisory does not state that authentication is required; therefore it is inferred that access to the router’s web interface is needed to supply the malicious payload, but the attack can be launched remotely from any client that can reach the management interface. At present, the flaw is not catalogued in the CISA KEV database.

Generated by OpenCVE AI on June 18, 2026 at 09:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to a firmware release that removes the command injection flaw.
  • If no patch is available, disable the PPTP Pass‑Thru option through the web interface to eliminate the vulnerable code path.
  • Restrict management‑interface access to trusted IP addresses or the local network only, and consider segmenting the router using VLANs or firewall rules.
  • Monitor the cstecgi.cgi endpoint for anomalous requests or logs indicating exploitation attempts, and apply rate‑limiting or intrusion‑prevention measures.
  • Apply perimeter network controls to block external connections to the router’s management ports if possible.

Generated by OpenCVE AI on June 18, 2026 at 09:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 30 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:totolink:a3300r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:*

Mon, 30 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a3300r
Vendors & Products Totolink a3300r

Mon, 30 Mar 2026 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument pptpPassThru results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Title Totolink A3300R Parameter cstecgi.cgi setVpnPassCfg command injection
First Time appeared Totolink
Totolink a3300r Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3300r Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3300r A3300r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-30T13:58:27.213Z

Reserved: 2026-03-29T17:50:56.050Z

Link: CVE-2026-5105

cve-icon Vulnrichment

Updated: 2026-03-30T13:58:21.503Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-30T04:16:09.680

Modified: 2026-06-17T10:58:26.677

Link: CVE-2026-5105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T09:45:15Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')