📦 A3300r Firmware

by Totolink

🔍 What is A3300r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-55895

CRITICAL CVSS 9.1 Dec 15, 2025

This vulnerability allows unauthenticated remote attackers to bypass access controls on TOTOLINK routers. Attackers can send malicious payloads to vulnerable interfaces without logging in, potentially...

CVE-2024-24326

CRITICAL CVSS 9.8 Jan 30, 2024

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the setStaticDhcpRules fu...

CVE-2024-24328

CRITICAL CVSS 9.8 Jan 30, 2024

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the setMacFilterRules fun...

CVE-2024-24330

CRITICAL CVSS 9.8 Jan 30, 2024

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this by injecting malicious com...

CVE-2024-24332

CRITICAL CVSS 9.8 Jan 30, 2024

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers, allowing attackers to execute arbitrary commands via the url parameter in the setUrlFilterRules function. It affects us...

CVE-2024-23060

CRITICAL CVSS 9.8 Jan 11, 2024

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers via the ip parameter in the setDmzCfg function. Attackers can execute arbitrary commands with root privileges, potential...

CVE-2024-22942

CRITICAL CVSS 9.8 Jan 11, 2024

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this by sending specially craft...

CVE-2024-23058

CRITICAL CVSS 9.8 Jan 11, 2024

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands via the pass parameter in the setTr069Cfg function. Attackers can ga...

CVE-2023-46993

CRITICAL CVSS 9.8 Oct 31, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3300R routers by exploiting improper input validation in the setLedCfg request. Attackers can gain full control of...

CVE-2023-46976

CRITICAL CVSS 9.8 Oct 31, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3300R routers by injecting malicious commands into the file_name parameter during firmware upload. Attackers can g...

CVE-2023-37170

CRITICAL CVSS 9.8 Jul 7, 2023

This vulnerability allows unauthenticated attackers to execute arbitrary commands on TOTOLINK A3300R routers by manipulating the lang parameter in the setLanguageCfg function. Attackers can gain full ...

CVE-2023-37172

CRITICAL CVSS 9.8 Jul 7, 2023

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this by sending specially craft...

CVE-2023-31729

CRITICAL CVSS 9.8 May 18, 2023

CVE-2023-31729 is a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device via the /cgi-bin/cstecgi.cgi endpoint. This affects use...

CVE-2025-12258

HIGH CVSS 8.8 Oct 27, 2025

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3300R routers by exploiting a stack-based buffer overflow in the setOpModeCfg function. Attackers can send specially c...

CVE-2025-12260

HIGH CVSS 8.8 Oct 27, 2025

A stack-based buffer overflow vulnerability in TOTOLINK A3300R routers allows remote attackers to execute arbitrary code by manipulating the 'enable' parameter in the setSyslogCfg function. This affec...

CVE-2025-12239

HIGH CVSS 8.8 Oct 27, 2025

A remote buffer overflow vulnerability exists in TOTOLINK A3300R routers through the setDdnsCfg function in cstecgi.cgi. Attackers can exploit this to execute arbitrary code or crash devices. All user...

CVE-2025-12241

HIGH CVSS 8.8 Oct 27, 2025

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3300R routers by exploiting a stack-based buffer overflow in the language configuration handler. Attackers can send sp...

CVE-2024-7331

HIGH CVSS 8.8 Aug 1, 2024

This critical vulnerability in TOTOLINK A3300R routers allows remote attackers to execute arbitrary code via a buffer overflow in the UploadCustomModule function. Attackers can exploit this by sending...

CVE-2023-46992

HIGH CVSS 7.5 Oct 31, 2023

CVE-2023-46992 is an authentication bypass vulnerability in TOTOLINK A3300R routers that allows unauthenticated attackers to reset critical passwords by accessing specific web pages. This affects user...

CVE-2025-55901

MEDIUM CVSS 6.5 Dec 15, 2025

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3300R routers by injecting malicious input into the host_time parameter of the NTPSyncWithHost function. Attackers...