Description
A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
Timeline
| 2026-03-29: | Advisory disclosed |
| 2026-03-29: | VulDB entry created |
| 2026-03-29: | VulDB entry last update |
Credits
LtzHuster2 (VulDB User)
References
vuldb.com/vuln/354127 (VDB-354127 | Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection)
vuldb.com/vuln/354127/cti (VDB-354127 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/779129 (Submit #779129 | Totolink A3300R 17.0.0cu.557_b20221024 Command Injection)
github.com/...zheng/vul_db/blob/main/A3300R/vul_40/README.md
www.totolink.net/