CVE-2026-5178: Totolink A3300R cstecgi.cgi setIptvCfg command injection
A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557b20221024. Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument vlanPriLan3 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5178?
CVE-2026-5178 is classified as a high-severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-5178?
To mitigate CVE-2026-5178, it is recommended to update the Totolink A3300R to the latest firmware version.
What specific function is affected by CVE-2026-5178?
CVE-2026-5178 affects the setIptvCfg function in the cstecgi.cgi file.
What is the impact of exploiting CVE-2026-5178?
Exploitation of CVE-2026-5178 can allow remote attackers to execute arbitrary commands on the affected device.
Which version of Totolink A3300R is vulnerable to CVE-2026-5178?
The vulnerable version of Totolink A3300R is 17.0.0cu.557_b20221024.