CVE-2026-5104

MEDIUM

Totolink A3300R cstecgi.cgi setStaticRoute command injection

Title source: cna

Description

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStaticRoute of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ip leads to command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

Scores

CVSS v3 6.3
EPSS 0.0216
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-74 CWE-77
Status published
Products (2)
Totolink/A3300R 17.0.0cu.557_b20221024
totolink/a3300r_firmware 17.0.0cu.557_b20221024
Published Mar 30, 2026
Tracked Since Mar 30, 2026