PT-2026-28755 · Totolink · A3300R

Ltzhuster2

·

Published

2026-03-29

·

Updated

2026-03-29

·

CVE-2026-5101

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was identified in Totolink A3300R 17.0.0cu.557 b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5101

Affected Products

A3300R