cbcvebase.

Totolink A3300R Firmware vulnerabilities

64 known vulnerabilities affecting totolink/a3300r_firmware.

Total CVEs
64
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL32HIGH14MEDIUM18

Vulnerabilities

Page 2 of 4
CVE-2024-24327P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24327 [CRITICAL] CWE-78 CVE-2024-24327: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.
nvd
CVE-2024-24326P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24326 [CRITICAL] CWE-78 CVE-2024-24326: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.
nvd
CVE-2024-22942P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-11
CVE-2024-22942 [CRITICAL] CWE-78 CVE-2024-22942: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function.
nvd
CVE-2024-23057P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-11
CVE-2024-23057 [CRITICAL] CWE-78 CVE-2024-23057: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function.
nvd
CVE-2026-31178P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-23
CVE-2026-31178 [CRITICAL] CWE-78 CVE-2026-31178: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31175P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-23
CVE-2026-31175 [CRITICAL] CWE-77 CVE-2026-31175: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31181P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-23
CVE-2026-31181 [CRITICAL] CWE-78 CVE-2026-31181: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31177P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-23
CVE-2026-31177 [CRITICAL] CWE-78 CVE-2026-31177: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31170P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-09
CVE-2026-31170 [CRITICAL] CWE-77 CVE-2026-31170: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2025-12240P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242025-10-27
CVE-2025-12240 [CRITICAL] CWE-119 CVE-2025-12240: A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects t A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-12258P2HIGHCVSS 8.8v17.0.0cu.557_b202210242025-10-27
CVE-2025-12258 [HIGH] CWE-119 CVE-2025-12258: A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. Impacted is the function set A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. Impacted is the function setOpModeCfg of the file /cgi-bin/cstecgi.cg of the component POST Parameter Handler. The manipulation of the argument opmode results in stack-based buffer overflow. The attack may be performed from remote.
nvd
CVE-2023-37173P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242023-07-07
CVE-2023-37173 [CRITICAL] CWE-78 CVE-2023-37173: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.
nvd
CVE-2023-37171P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242023-07-07
CVE-2023-37171 [CRITICAL] CWE-78 CVE-2023-37171: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
nvd
CVE-2024-23058P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-11
CVE-2024-23058 [CRITICAL] CWE-78 CVE-2024-23058: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.
nvd
CVE-2024-24325P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24325 [CRITICAL] CWE-78 CVE-2024-24325: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.
nvd
CVE-2024-24331P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24331 [CRITICAL] CWE-78 CVE-2024-24331: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.
nvd
CVE-2024-24330P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242024-01-30
CVE-2024-24330 [CRITICAL] CWE-78 CVE-2024-24330: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.
nvd
CVE-2023-46976P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242023-10-31
CVE-2023-46976 [CRITICAL] CWE-77 CVE-2023-46976: TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in t TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.
nvd
CVE-2025-12239P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242025-10-27
CVE-2025-12239 [CRITICAL] CWE-119 CVE-2025-12239: A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is th A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Executing manipulation can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.
nvd
CVE-2023-37170P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242023-07-07
CVE-2023-37170 [CRITICAL] CWE-78 CVE-2023-37170: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code exe TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
nvd