Impact
A command injection flaw resides in the setIptvCfg function inside /cgi-bin/cstecgi.cgi on Totolink A3300R routers. By manipulating the vlanPriLan3 argument, an attacker can cause the router’s web server process to execute arbitrary operating‑system commands. The injected commands run with the privileges granted to the web service, allowing full control over the device and the surrounding network. This weakness is identified as CWE‑74 and CWE‑77.
Affected Systems
Affected devices are Totolink A3300R routers with firmware 17.0.0cu.557_b20221024. The vulnerability is present in the setIptvCfg code and applies to all builds that have not been updated beyond this version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while an EPSS of 4% suggests that exploitation is feasible but not prevalent. The vulnerability is not listed in the CISA KEV catalog. Public exploit code demonstrates that a remote attacker can trigger the injection by sending crafted HTTP requests to the router’s web interface, typically requiring network access to the management interface and possibly no authentication, though credential prerequisites are not explicitly stated.
OpenCVE Enrichment