Impact
The setVpnPassCfg function within cstecgi.cgi processes the pptpPassThru argument without adequate validation, allowing an attacker to embed arbitrary operating‑system commands in that parameter. When the router receives such a crafted value, the commands execute with the privileges of the web server process, effectively granting remote command execution. This weakness permits an attacker to compromise the device, exfiltrate data, or pivot to the internal network.
Affected Systems
The flaw affects all Totolink A3300R routers running firmware 17.0.0cu.557_b20221024. No other firmware versions or models are listed in the advisory.
Risk and Exploitability
With a CVSS base score of 5.3 the vulnerability is rated moderate, and an EPSS score of 4% indicates a relatively low exploitation likelihood in the wild. The advisory does not state that authentication is required; therefore it is inferred that access to the router’s web interface is needed to supply the malicious payload, but the attack can be launched remotely from any client that can reach the management interface. At present, the flaw is not catalogued in the CISA KEV database.
OpenCVE Enrichment