CVE-2026-5101
HIGH WAF: High
CVSS 8.8
Published: 2026-03-29
CWE-77 CWE-78
A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
WAF Coverage Analysis
Command Injection
High WAF Coverage
OWASP: A03:2021 Injection
932xxx - Remote Code Execution
OS Command Injection
High WAF Coverage
OWASP: A03:2021 Injection
932xxx - Remote Code Execution
Affected Software
| Vendor | Product | Version |
|---|---|---|
| totolink | a3300r_firmware | 17.0.0cu.557_b20221024 |
References
- github.com (Exploit, Third Party Advisory)
- vuldb.com (VDB Entry, Third Party Advisory)
- vuldb.com (Third Party Advisory, VDB Entry)
- vuldb.com (Third Party Advisory, VDB Entry)
- www.totolink.net (Product)