Totolink A3300R Firmware vulnerabilities
64 known vulnerabilities affecting totolink/a3300r_firmware.
Total CVEs
64
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL32HIGH14MEDIUM18
Vulnerabilities
Page 3 of 4
CVE-2026-31170P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242026-04-09
CVE-2026-31170 [CRITICAL] CWE-77 CVE-2026-31170: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2023-31729P2CRITICALCVSS 9.8v17.0.0cu.5572023-05-18
CVE-2023-31729 [CRITICAL] CWE-77 CVE-2023-31729: TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
nvd
CVE-2023-46993P2CRITICALCVSS 9.8v17.0.0cu.557_b202210242023-10-31
CVE-2023-46993 [CRITICAL] CWE-77 CVE-2023-46993: In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verifica
In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.
nvd
CVE-2025-55895P3CRITICALCVSS 9.1v17.0.0cu.557_b202210242025-12-15
CVE-2025-55895 [CRITICAL] CWE-284 CVE-2025-55895: TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519
TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).
nvd
CVE-2024-27521P3HIGHCVSS 8.0v17.0.0cu.557_b202210242024-03-26
CVE-2024-27521 [HIGH] CWE-78 CVE-2024-27521: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail, exploitation allows unauthenticated, remote attackers to execute arbitrary syst
nvd
CVE-2023-46992P3HIGHCVSS 7.5v17.0.0cu.557_b202210242023-10-31
CVE-2023-46992 [HIGH] CWE-863 CVE-2023-46992: TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are abl
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.
nvd
CVE-2026-31159P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31159 [MEDIUM] CWE-77 CVE-2026-31159: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2025-55901P3MEDIUMCVSS 6.5v17.0.0cu.596_b202505152025-12-15
CVE-2025-55901 [MEDIUM] CWE-77 CVE-2025-55901: TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWi
TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.
nvd
CVE-2026-31174P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31174 [MEDIUM] CWE-77 CVE-2026-31174: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31179P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31179 [MEDIUM] CWE-77 CVE-2026-31179: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunPort parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31165P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31165 [MEDIUM] CWE-77 CVE-2026-31165: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31173P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31173 [MEDIUM] CWE-77 CVE-2026-31173: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the interval parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31167P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31167 [MEDIUM] CWE-77 CVE-2026-31167: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the mode parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31168P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31168 [MEDIUM] CWE-77 CVE-2026-31168: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the recHour parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31176P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31176 [MEDIUM] CWE-77 CVE-2026-31176: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun_user parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31172P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31172 [MEDIUM] CWE-77 CVE-2026-31172: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31160P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31160 [MEDIUM] CWE-77 CVE-2026-31160: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the provider parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31163P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31163 [MEDIUM] CWE-77 CVE-2026-31163: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the dhcpMtu parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31164P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31164 [MEDIUM] CWE-77 CVE-2026-31164: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi.
nvd
CVE-2026-31162P3MEDIUMCVSS 6.5v17.0.0cu.557_b202210242026-04-23
CVE-2026-31162 [MEDIUM] CWE-77 CVE-2026-31162: An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the ttlWay parameter to /cgi-bin/cstecgi.cgi.
nvd