CVE-2026-31165

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName parameter to /cgi-bin/cstecgi.cgi.

medium 6.5 CVSS 3.1
Published: Apr 23, 2026
Modified: Apr 24, 2026
Vendor: Totolink
Product: A3300R Firmware
Versions: 17.0.0cu.557_b20221024

Description

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName parameter to /cgi-bin/cstecgi.cgi.

References

Related CVEs