An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi.
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 65.00 |
| Exploitation signal(PoC exists) | ×1.20 |
| VPI | 78.00 |
VPI formula vpi-v1