CVE-2026-5176: Totolink A3300R cstecgi.cgi setSyslogCfg command injection
A security flaw has been discovered in Totolink A3300R 17.0.0cu.557b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument provided results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5176?
CVE-2026-5176 has a high severity rating due to the potential for command injection affecting the Totolink A3300R device.
How do I fix CVE-2026-5176?
To mitigate CVE-2026-5176, it is recommended to upgrade the Totolink A3300R firmware to a patched version that resolves the vulnerability.
Which devices are affected by CVE-2026-5176?
CVE-2026-5176 specifically affects the Totolink A3300R running version 17.0.0cu.557_b20221024.
What kind of attack can be executed through CVE-2026-5176?
CVE-2026-5176 allows attackers to execute arbitrary commands on the device through the vulnerable setSyslogCfg function.
Is there a workaround for CVE-2026-5176?
Currently, the best recommendation for CVE-2026-5176 is to apply any available firmware updates rather than relying on workarounds.