CVE-2026-5103 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setUPnPCfg enable command injection (EUVD-2026-17053)
A vulnerability marked as critical has been reported in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection.
This vulnerability is tracked as CVE-2026-5103. The attack is possible to be carried out remotely. Moreover, an exploit is present.