CVE-2026-5102 | Totolink A3300R 17.0.0cu.557_b20221024 Parameter /cgi-bin/cstecgi.cgi setSmartQosCfg qos_up_bw command injection (EUVD-2026-17050)
A vulnerability labeled as critical has been found in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection.
This vulnerability is identified as CVE-2026-5102. The attack can be executed remotely. Additionally, an exploit exists.