PT-2026-28756 · Totolink · Totolink A3300R

Ltzhuster2

·

Published

2026-03-30

·

Updated

2026-03-30

·

CVE-2026-5102

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Totolink A3300R version 17.0.0cu.557 b20221024
Description A security flaw exists in the Totolink A3300R router. This issue involves a command injection impacting the setSmartQosCfg function within the /cgi-bin/cstecgi.cgi file of the Parameter Handler component. The qos up bw argument can be manipulated to execute commands remotely. The exploit for this issue has been publicly released.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /cgi-bin/cstecgi.cgi file.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5102

Affected Products

Totolink A3300R