5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Basic Information
ID
CVE-2026-5101
Source
VulDB
Published
Mar 29, 2026 at 23:00
Modified
Mar 30, 2026 at 14:52
Affected Product
Vendor
Totolink
Product
A3300R
Version
17.0.0cu.557_b20221024
Affected Versions
Totolink A3300R 17.0.0cu.557_b20221024