Impact
The Totolink A3300R router with firmware 17.0.0cu.557_b20221024 contains a flaw in the setWiFiBasicCfg function of /cgi-bin/cstecgi.cgi. Manipulating the rxRate argument allows an attacker to inject operating‑system commands that are executed by the CGI process, giving remote code execution on the device.
Affected Systems
The vulnerability affects the Totolink A3300R router running firmware 17.0.0cu.557_b20221024, with no other vendors or product versions listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of 2% shows a modest likelihood of exploitation. The exploit is not yet listed in the CISA KEV catalog, suggesting no confirmed widespread attacks. The description states the attack may be launched remotely; authentication requirements are not specified. If an attacker can craft a request to cstecgi.cgi with a malicious rxRate value, the injected commands may run with the privileges of the CGI process, potentially compromising the router’s configuration or operation.
OpenCVE Enrichment