A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Mar 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. | |
| Title | Totolink A3300R cstecgi.cgi setUPnPCfg command injection | |
| First Time appeared |
Totolink
Totolink a3300r Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink
Totolink a3300r Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-30T01:00:20.917Z
Reserved: 2026-03-29T17:50:50.164Z
Link: CVE-2026-5103
No data.
Status : Received
Published: 2026-03-30T02:16:15.840
Modified: 2026-03-30T02:16:15.840
Link: CVE-2026-5103
No data.
OpenCVE Enrichment
No data.