Impact
A flaw exists in the setVpnPassCfg function of the /cgi-bin/cstecgi.cgi component that handles the pptpPassThru parameter. An attacker who can supply a crafted value can inject arbitrary operating‑system commands that are subsequently executed by the router. This vulnerability satisfies both command injection and operating‑system command injection weakness classes, allowing the attacker to run code with the privileges of the web server process and potentially compromise the device and the internal network.
Affected Systems
The affected product is the Totolink A3300R router running firmware version 17.0.0cu.557_b20221024. No other products or firmware revisions are listed in the advisory.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity, and the EPSS score of <1 % suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The advisory states that the attack can be initiated remotely, but it does not clarify whether authentication or administrative privileges are required; it is therefore inferred that access to the router’s web interface may be necessary. Once reached, a crafted HTTP request carrying a malicious pptpPassThru value can trigger the injection with no further conditions noted.
OpenCVE Enrichment