CVE-2026-5104: Totolink A3300R cstecgi.cgi setStaticRoute command injection
A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557b20221024. Impacted is the function setStaticRoute of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ip leads to command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5104?
CVE-2026-5104 is classified as a critical vulnerability as it allows for command injection via the setStaticRoute function.
How do I fix CVE-2026-5104?
To fix CVE-2026-5104, update the Totolink A3300R firmware to the latest version that addresses this vulnerability.
What systems are affected by CVE-2026-5104?
CVE-2026-5104 affects Totolink A3300R devices running firmware version 17.0.0cu.557_b20221024.
What type of attack is possible with CVE-2026-5104?
CVE-2026-5104 enables attackers to perform command injection attacks through manipulated IP arguments.
Who is the vendor associated with CVE-2026-5104?
The vendor associated with CVE-2026-5104 is Totolink, which manufactures the affected A3300R router.