Description
A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument vlanPriLan3 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Published: 2026-03-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution via command injection
Action: Patch ASAP
AI Analysis

Impact

A command injection flaw exists in the setIptvCfg function of /cgi-bin/cstecgi.cgi on affected Totolink A3300R routers. Manipulating the vlanPriLan3 parameter lets an attacker embed and execute arbitrary operating‑system commands, granting complete control over the device and potentially exposing connected network resources. The vulnerability is categorized as CWE‑74 and CWE‑77 and can lead to compromise of confidentiality, integrity, and availability.

Affected Systems

The issue affects Totolink A3300R routers running firmware version 17.0.0cu.557_b20221024. Any device operating this firmware, or earlier builds that have not applied subsequent security fixes, is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of 1% suggests low overall exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but a publicly available exploit demonstrates that remote attackers can trigger the injection by sending crafted requests to the device’s web interface. Because authentication requirements are not specified, the risk remains that unauthenticated or authenticated attackers could exploit the flaw without additional credentials.

Generated by OpenCVE AI on April 6, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router to the latest firmware available from the Totolink website, ensuring version removal of the command injection bug.
  • If no firmware update is possible, block external access to the /cgi-bin/cstecgi.cgi endpoint with firewall rules or disable Internet management features on the router.
  • Ensure that the vlanPriLan3 parameter or similar inputs are validated and sanitized on the device, or monitor logs for suspicious command injection attempts.
  • Verify the patch by attempting to execute a harmless test command through the vulnerable endpoint and confirming it is no longer processed.

Generated by OpenCVE AI on April 6, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:totolink:a3300r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:*

Thu, 02 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a3300r
Vendors & Products Totolink a3300r

Tue, 31 Mar 2026 04:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument vlanPriLan3 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Title Totolink A3300R cstecgi.cgi setIptvCfg command injection
First Time appeared Totolink
Totolink a3300r Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3300r Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A3300r A3300r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-02T14:54:34.752Z

Reserved: 2026-03-30T18:53:46.535Z

Link: CVE-2026-5178

cve-icon Vulnrichment

Updated: 2026-04-02T14:54:29.529Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-31T04:16:45.660

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-5178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-07T08:08:10Z

Weaknesses