Totolink A3300R Firmware vulnerabilities
64 known vulnerabilities affecting totolink/a3300r_firmware.
Total CVEs
64
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL32HIGH14MEDIUM18
Vulnerabilities
Page 2 of 4
CVE-2023-37171P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242023-07-07
CVE-2023-37171 [CRITICAL] CWE-78 CVE-2023-37171: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
nvd
CVE-2024-23061P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-11
CVE-2024-23061 [CRITICAL] CWE-78 CVE-2024-23061: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.
nvd
CVE-2024-23059P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-11
CVE-2024-23059 [CRITICAL] CWE-78 CVE-2024-23059: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnsCfg function.
nvd
CVE-2024-24333P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24333 [CRITICAL] CWE-78 CVE-2024-24333: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.
nvd
CVE-2024-23058P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-11
CVE-2024-23058 [CRITICAL] CWE-78 CVE-2024-23058: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.
nvd
CVE-2024-24327P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24327 [CRITICAL] CWE-78 CVE-2024-24327: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.
nvd
CVE-2024-24326P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24326 [CRITICAL] CWE-78 CVE-2024-24326: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.
nvd
CVE-2025-12239P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242025-10-27
CVE-2025-12239 [CRITICAL] CWE-119 CVE-2025-12239: A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is th
A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Executing manipulation can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.
nvd
CVE-2024-24325P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24325 [CRITICAL] CWE-78 CVE-2024-24325: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.
nvd
CVE-2024-22942P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-11
CVE-2024-22942 [CRITICAL] CWE-78 CVE-2024-22942: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function.
nvd
CVE-2024-23057P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-11
CVE-2024-23057 [CRITICAL] CWE-78 CVE-2024-23057: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function.
nvd
CVE-2023-37170P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242023-07-07
CVE-2023-37170 [CRITICAL] CWE-78 CVE-2023-37170: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code exe
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
nvd
CVE-2024-24330P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24330 [CRITICAL] CWE-78 CVE-2024-24330: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.
nvd
CVE-2023-46976P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242023-10-31
CVE-2023-46976 [CRITICAL] CWE-77 CVE-2023-46976: TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in t
TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.
nvd
CVE-2024-7331P2HIGHCVSS 8.8v17.0.0cu.557_b202210242024-08-01
CVE-2024-7331 [HIGH] CWE-120 CVE-2024-7331: A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affe
A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-
nvd
CVE-2024-24331P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24331 [CRITICAL] CWE-78 CVE-2024-24331: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.
nvd
CVE-2026-31177P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-23
CVE-2026-31177 [CRITICAL] CWE-78 CVE-2026-31177: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31178P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-23
CVE-2026-31178 [CRITICAL] CWE-78 CVE-2026-31178: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31175P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-23
CVE-2026-31175 [CRITICAL] CWE-77 CVE-2026-31175: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31181P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-23
CVE-2026-31181 [CRITICAL] CWE-78 CVE-2026-31181: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi.
nvd