CVE-2026-5101 | Totolink A3300R 17.0.0cu.557_b20221024 Parameter /cgi-bin/cstecgi.cgi setLanCfg lanIp command injection (EUVD-2026-17048)
A vulnerability identified as critical has been detected in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection.
This vulnerability is referenced as CVE-2026-5101. Remote exploitation of the attack is possible. Furthermore, an exploit is available.