Impact
The vulnerability allows attackers to inject arbitrary operating‑system commands by manipulating the hostTime parameter in the NTPSyncWithHost function of /cgi-bin/cstecgi.cgi. This represents an OS Command Injection weakness (CWE‑74) caused by improper handling of user supplied input, and an improper use of system commands (CWE‑77). The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Systems
The flaw exists in Totolink WA300 routers running firmware version 5.2cu.7112_B20190227. Only devices released with this specific firmware revision are impacted; versions without this revision are not listed as affected.
Risk and Exploitability
A CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Publicly disclosed exploits exist, showing that attackers could weaponise the flaw. Remote attackers can construct a malicious HTTP request to /cgi-bin/cstecgi.cgi, supplying a crafted hostTime value that results in arbitrary command execution on the router’s operating system.
OpenCVE Enrichment