PT-2026-28756 · Totolink · Totolink A3300R

·

CVE-2026-5102

·

Publicado

2026-03-30

·

Atualizado

2026-03-30

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink A3300R version 17.0.0cu.557 b20221024
Description A security flaw exists in the Totolink A3300R router. This issue involves a command injection impacting the setSmartQosCfg function within the /cgi-bin/cstecgi.cgi file of the Parameter Handler component. The qos up bw argument can be manipulated to execute commands remotely. The exploit for this issue has been publicly released.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /cgi-bin/cstecgi.cgi file.

Exploit

Correção

Command Injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-5102

Produtos afetados

Totolink A3300R