Impact
A weakness exists in the setWiFiBasicCfg function of the /cgi-bin/cstecgi.cgi script on the Totolink A3300R router. Manipulating the rxRate argument allows an attacker to inject operating‑system commands, which can result in arbitrary command execution on the device. The vulnerability is serious because it enables remote execution of code that could compromise the router’s configuration, exfiltrate sensitive data, or disrupt network functionality.
Affected Systems
The affected product is the Totolink A3300R router running firmware version 17.0.0cu.557_b20221024. No other vendor or product versions are listed as impacted in the available data.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity, while the EPSS score of 1% indicates a relatively low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. The description states the attack may be launched remotely, but it does not specify whether authentication is required. If an attacker can craft a request to cstecgi.cgi with a malicious rxRate parameter, the injected commands could execute with the privileges of the CGI process, potentially compromising the router. The exact attack vector is inferred from the available description of a remote command injection scenario.
OpenCVE Enrichment