Impact
A command injection flaw exists in the setIptvCfg function of /cgi-bin/cstecgi.cgi on affected Totolink A3300R routers. Manipulating the vlanPriLan3 parameter lets an attacker embed and execute arbitrary operating‑system commands, granting complete control over the device and potentially exposing connected network resources. The vulnerability is categorized as CWE‑74 and CWE‑77 and can lead to compromise of confidentiality, integrity, and availability.
Affected Systems
The issue affects Totolink A3300R routers running firmware version 17.0.0cu.557_b20221024. Any device operating this firmware, or earlier builds that have not applied subsequent security fixes, is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of 1% suggests low overall exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but a publicly available exploit demonstrates that remote attackers can trigger the injection by sending crafted requests to the device’s web interface. Because authentication requirements are not specified, the risk remains that unauthenticated or authenticated attackers could exploit the flaw without additional credentials.
OpenCVE Enrichment