CVE-2026-31164: Command Injection
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31164?
CVE-2026-31164 is classified as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2026-31164?
To remediate CVE-2026-31164, update the ToToLink A3300R firmware to a version that is not affected by this vulnerability.
What are the potential impacts of exploiting CVE-2026-31164?
Exploiting CVE-2026-31164 can allow an attacker to execute arbitrary commands on the affected device.
What version of the firmware is affected by CVE-2026-31164?
The vulnerable version of the firmware in CVE-2026-31164 is ToToLink A3300R firmware v17.0.0cu.557_B20221024.
Is there a known workaround for CVE-2026-31164?
As of now, the recommended solution for CVE-2026-31164 is to update the firmware to a secure version, as there are no known effective workarounds.