Impact
The flaw resides in the vsetTr069Cfg function within the /cgi-bin/cstecgi.cgi script of Totolink A3300R firmware 17.0.0cu.557_B20221024. An attacker can manipulate the stun_pass argument, causing an operating‑system command injection that falls under CWE-77 and CWE-78. Successful exploitation leads to arbitrary OS command execution and full control over the device.
Affected Systems
The vulnerability affects the Totolink A3300R router running firmware version 17.0.0cu.557_B20221024. The exposed CGI endpoint is named /cgi-bin/cstecgi.cgi and is specific to this router model.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of about 1.7% (0.01744) and absence from the CISA KEV catalog suggest limited current exploitation. The risk escalates if the CGI endpoint is externally reachable; no explicit authentication requirements are stated, so it is inferred that an attacker with network access to the script could exploit the weakness without additional credentials.
OpenCVE Enrichment