VendorsTOTOLINKa3300rall versions
Vulnerabilities

TOTOLINK A3300R

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

64CVEs
CVE-2026-5104
Totolink A3300R cstecgi.cgi setStaticRoute command injection
Published 2026-03-30 · Analyzed
8.8EPSS 0.027
CVE-2026-5177
Totolink A3300R cstecgi.cgi setWiFiBasicCfg command injection
Published 2026-03-31 · Analyzed
8.8EPSS 0.026
CVE-2026-5101
Totolink A3300R Parameter cstecgi.cgi setLanCfg command injection
Published 2026-03-29 · Analyzed
8.8EPSS 0.024
CVE-2026-5102
Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection
Published 2026-03-30 · Analyzed
8.8EPSS 0.024
CVE-2024-27521
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail, exploitation allows unauthenticated, remote attackers to execute arbitrary system commands with administrative privileges (i.e., as user "root").
Published 2024-03-26 · Analyzed
8.0EPSS 0.015
CVE-2023-46992
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.
Published 2023-10-31 · Modified
7.5EPSS 0.005
CVE-2025-55901
TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.
Published 2025-12-15 · Analyzed
6.5EPSS 0.011
CVE-2026-31176
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun_user parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31179
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunPort parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31159
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31163
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the dhcpMtu parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31160
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the provider parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31174
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31173
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the interval parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31172
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31171
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the url parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31162
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the ttlWay parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31169
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the week parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31168
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the recHour parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31167
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the mode parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31165
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31164
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2026-31166
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the hour parameter to /cgi-bin/cstecgi.cgi.
Published 2026-04-23 · Analyzed
6.5EPSS 0.003
CVE-2024-7155
TOTOLINK A3300R shadow.sample hard-coded password
Published 2024-07-28 · Modified
4.7EPSS 0.003
← Prev2 / 2