CVE-2026-31177

· NIST NVD ↗

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.

CRITICAL
CVSS severity
9.8
CVSS base score
2026-04-23
Published

CWE codes

CWE-78

Affected products

totolink:a3300r_firmwaretotolink:a3300r

Sources