PT-2026-29187 · Totolink · A3300R

Lvhw

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-5177

CVSS v3.1

6.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A weakness has been identified in Totolink A3300R 17.0.0cu.557 b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

Exploit

Fix

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5177

Affected Products

A3300R