Vulnerability Description
A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | A3300R Firmware | 17.0.0cu.557_b20221024 |
| Totolink | A3300R | - |
Related Weaknesses (CWE)
References
- https://github.com/Litengzheng/vul_db/blob/main/A3300R/vul_39/README.mdExploitThird Party Advisory
- https://vuldb.com/submit/779128VDB EntryThird Party Advisory
- https://vuldb.com/vuln/354126Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/354126/ctiThird Party AdvisoryVDB Entry
- https://www.totolink.net/Product
FAQ
What is CVE-2026-5101?
CVE-2026-5101 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of t...
How severe is CVE-2026-5101?
CVE-2026-5101 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5101?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink A3300R Firmware, Totolink A3300R.