VendorsTOTOLINKa3300rall versions
Vulnerabilities

TOTOLINK A3300R

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

64CVEs
CVE-2024-24329
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.
Published 2024-01-30 · Modified
9.8EPSS 0.062
CVE-2024-24328
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.
Published 2024-01-30 · Modified
9.8EPSS 0.062
CVE-2025-52046
Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
Published 2025-07-17 · Analyzed
9.8EPSS 0.055
CVE-2026-5176
Totolink A3300R cstecgi.cgi setSyslogCfg command injection
Published 2026-03-31 · Analyzed
9.8EPSS 0.021
CVE-2023-37172
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
Published 2023-07-07 · Modified
9.8EPSS 0.020
CVE-2023-37173
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.
Published 2023-07-07 · Modified
9.8EPSS 0.020
CVE-2023-37171
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
Published 2023-07-07 · Modified
9.8EPSS 0.020
CVE-2024-24325
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.
Published 2024-01-30 · Modified
9.8EPSS 0.017
CVE-2024-24332
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.
Published 2024-01-30 · Modified
9.8EPSS 0.017
CVE-2024-23059
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnsCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2024-23061
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2024-24333
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.
Published 2024-01-30 · Modified
9.8EPSS 0.017
CVE-2024-23060
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2023-37170
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
Published 2023-07-07 · Modified
9.8EPSS 0.017
CVE-2024-24326
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.
Published 2024-01-30 · Modified
9.8EPSS 0.016
CVE-2024-24327
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.
Published 2024-01-30 · Modified
9.8EPSS 0.016
CVE-2024-23057
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.016
CVE-2024-22942
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.016
CVE-2024-23058
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.016
CVE-2024-24331
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.
Published 2024-01-30 · Modified
9.8EPSS 0.016
CVE-2024-24330
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.
Published 2024-01-30 · Modified
9.8EPSS 0.015
CVE-2023-46993
In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.
Published 2023-10-31 · Modified
9.8EPSS 0.015
CVE-2023-46976
TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.
Published 2023-10-31 · Modified
9.8EPSS 0.015
CVE-2023-31729
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
Published 2023-05-18 · Modified
9.8EPSS 0.013
CVE-2025-12239
TOTOLINK A3300R cstecgi.cgi setDdnsCfg buffer overflow
Published 2025-10-27 · Analyzed
9.8EPSS 0.008
CVE-2025-12240
TOTOLINK A3300R cstecgi.cgi setDmzCfg buffer overflow
Published 2025-10-27 · Analyzed
9.8EPSS 0.008
CVE-2026-31177
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
9.8EPSS 0.006
CVE-2026-31181
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
9.8EPSS 0.006
CVE-2026-31178
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
9.8EPSS 0.006
CVE-2026-31175
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
9.8EPSS 0.006
CVE-2026-31170
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-09 · Analyzed
9.8EPSS 0.006
CVE-2025-55895
TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).
Published 2025-12-15 · Analyzed
9.1EPSS 0.003
CVE-2024-7331
TOTOLINK A3300R cstecgi.cgi UploadCustomModule buffer overflow
Published 2024-08-01 · Analyzed
9.0EPSS 0.012
CVE-2025-12241
TOTOLINK A3300R POST Parameter cstecgi.cgi setLanguageCfg stack-based overflow
Published 2025-10-27 · Analyzed
9.0EPSS 0.009
CVE-2025-12260
TOTOLINK A3300R POST Parameter cstecgi.cgi setSyslogCfg stack-based overflow
Published 2025-10-27 · Analyzed
9.0EPSS 0.009
CVE-2025-12258
TOTOLINK A3300R POST Parameter cstecgi.cg setOpModeCfg stack-based overflow
Published 2025-10-27 · Analyzed
9.0EPSS 0.009
CVE-2025-12259
TOTOLINK A3300R POST Parameter cstecgi.cgi setScheduleCfg stack-based overflow
Published 2025-10-27 · Analyzed
9.0EPSS 0.009
CVE-2026-5178
Totolink A3300R cstecgi.cgi setIptvCfg command injection
Published 2026-03-31 · Analyzed
8.8EPSS 0.040
CVE-2026-5105
Totolink A3300R Parameter cstecgi.cgi setVpnPassCfg command injection
Published 2026-03-30 · Analyzed
8.8EPSS 0.040
CVE-2026-5103
Totolink A3300R cstecgi.cgi setUPnPCfg command injection
Published 2026-03-30 · Analyzed
8.8EPSS 0.040
1 / 2Next →