CVE-2026-5679Medium· 5.5▾ SunlitA security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command inje…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.7%
1.7% → 1.9%
A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. The exploit has been disclosed publicly and may be used.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2026-5692High· 7.3A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024
CVE-2026-5691High· 7.3A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024
CVE-2026-5690High· 7.3A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024
CVE-2026-5689High· 7.3A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024
CVE-2026-5688High· 7.3A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024