Vulnerability Description
A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument pptpPassThru results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | A3300R Firmware | 17.0.0cu.557_b20221024 |
| Totolink | A3300R | - |
Related Weaknesses (CWE)
References
- https://github.com/LvHongW/Vuln-of-totolink_A3300R/tree/main/A3300R_pptpPassThruExploitThird Party Advisory
- https://vuldb.com/submit/779143Permissions RequiredVDB Entry
- https://vuldb.com/vuln/354130Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/354130/ctiThird Party AdvisoryVDB Entry
- https://www.totolink.net/Product
FAQ
What is CVE-2026-5105?
CVE-2026-5105 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performi...
How severe is CVE-2026-5105?
CVE-2026-5105 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5105?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink A3300R Firmware, Totolink A3300R.