Home

Description

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi.

PUBLISHED Reserved 2026-03-09 | Published 2026-04-23 | Updated 2026-04-23 | Assigner mitre

References

github.com/...in/totolink-a3300r-inform-enable-cmd-injection exploit

github.com/...in/totolink-a3300r-inform-enable-cmd-injection

cve.org (CVE-2026-31174)

nvd.nist.gov (CVE-2026-31174)

Download JSON