CVE-2026-5102

MEDIUM

Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection

Title source: cna

Description

A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Scores

CVSS v3 6.3
EPSS 0.0216
EPSS Percentile 84.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-77
Status published
Products (2)
Totolink/A3300R 17.0.0cu.557_b20221024
totolink/a3300r_firmware 17.0.0cu.557_b20221024
Published Mar 30, 2026
Tracked Since Mar 30, 2026