Description
A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-03-31
Score: 5.3 Medium
EPSS: 2.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Totolink A3300R router with firmware 17.0.0cu.557_b20221024 contains a flaw in the setWiFiBasicCfg function of /cgi-bin/cstecgi.cgi. Manipulating the rxRate argument allows an attacker to inject operating‑system commands that are executed by the CGI process, giving remote code execution on the device.

Affected Systems

The vulnerability affects the Totolink A3300R router running firmware 17.0.0cu.557_b20221024, with no other vendors or product versions listed as impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of 2% shows a modest likelihood of exploitation. The exploit is not yet listed in the CISA KEV catalog, suggesting no confirmed widespread attacks. The description states the attack may be launched remotely; authentication requirements are not specified. If an attacker can craft a request to cstecgi.cgi with a malicious rxRate value, the injected commands may run with the privileges of the CGI process, potentially compromising the router’s configuration or operation.

Generated by OpenCVE AI on June 18, 2026 at 09:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor firmware update that resolves the command injection flaw (CWE‑74 and CWE‑77) in the setWiFiBasicCfg function.
  • Configure the router to perform strict input validation on the rxRate parameter and reject malformed values, following CWE‑74 recommendations.
  • Limit remote management to trusted IP addresses to reduce exposure.
  • Monitor the web server and system logs for abnormal requests to /cgi-bin/cstecgi.cgi and for evidence of command execution.

Generated by OpenCVE AI on June 18, 2026 at 09:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:totolink:a3300r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:*

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a3300r
Vendors & Products Totolink a3300r

Tue, 31 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A3300R cstecgi.cgi setWiFiBasicCfg command injection
First Time appeared Totolink
Totolink a3300r Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3300r Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3300r A3300r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-31T13:27:49.031Z

Reserved: 2026-03-30T18:53:43.654Z

Link: CVE-2026-5177

cve-icon Vulnrichment

Updated: 2026-03-31T13:27:43.726Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-31T03:15:59.297

Modified: 2026-06-17T10:58:33.040

Link: CVE-2026-5177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T09:45:15Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')