CVE-2026-5102: Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection
A security flaw has been discovered in Totolink A3300R 17.0.0cu.557b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qosupbw results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5102?
CVE-2026-5102 is classified as a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-5102?
To fix CVE-2026-5102, update your Totolink A3300R router to the latest firmware version provided by the manufacturer.
What component is affected by CVE-2026-5102?
CVE-2026-5102 affects the setSmartQosCfg function within the cstecgi.cgi file of the Totolink A3300R.
What are the potential impacts of CVE-2026-5102?
The potential impacts of CVE-2026-5102 include unauthorized command execution and compromised device security.
Is CVE-2026-5102 specific to certain firmware versions?
Yes, CVE-2026-5102 specifically affects Totolink A3300R version 17.0.0cu.557_b20221024.