A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
References
| Link | Resource |
|---|---|
| https://github.com/LvHongW/Vuln-of-totolink_A3300R/tree/main/A3300R_rxRate_cmd_inject | Exploit Third Party Advisory |
| https://vuldb.com/submit/779146 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/354245 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/354245/cti | Permissions Required VDB Entry |
| https://www.totolink.net/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
06 Apr 2026, 15:22
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/LvHongW/Vuln-of-totolink_A3300R/tree/main/A3300R_rxRate_cmd_inject - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/779146 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/354245 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/354245/cti - Permissions Required, VDB Entry | |
| References | () https://www.totolink.net/ - Product | |
| CPE | cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3300r:-:*:*:*:*:*:*:* |
|
| First Time |
Totolink a3300r
Totolink a3300r Firmware Totolink |
01 Apr 2026, 14:24
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
31 Mar 2026, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 03:15
Updated : 2026-04-29 01:00
NVD link : CVE-2026-5177
Mitre link : CVE-2026-5177
CVE.ORG link : CVE-2026-5177
JSON object : View
Products Affected
totolink
- a3300r
- a3300r_firmware
