Report: - Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection CVE-2026-5102

Report: - Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection CVE-2026-5102

CVE ID :CVE-2026-5102 Published : March 30, 2026, 12:16 a.m. | 46 minutes ago Description :A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 30, 2026
Impact: command injection