Home

Description

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter to /cgi-bin/cstecgi.cgi.

PUBLISHED Reserved 2026-03-09 | Published 2026-04-23 | Updated 2026-04-23 | Assigner mitre

References

github.com/...l/tree/main/totolink-a3300r-user-cmd-injection exploit

github.com/...l/tree/main/totolink-a3300r-user-cmd-injection

cve.org (CVE-2026-31172)

nvd.nist.gov (CVE-2026-31172)

Download JSON