A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. | |
| Title | Totolink A3300R cstecgi.cgi setWiFiBasicCfg command injection | |
| First Time appeared |
Totolink
Totolink a3300r Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:totolink:a3300r_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink
Totolink a3300r Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-31T02:00:21.538Z
Reserved: 2026-03-30T18:53:43.654Z
Link: CVE-2026-5177
No data.
Status : Received
Published: 2026-03-31T03:15:59.297
Modified: 2026-03-31T03:15:59.297
Link: CVE-2026-5177
No data.
OpenCVE Enrichment
No data.