VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
JVNDB-2026-003516     ( CVE-2026-2167 | CVE-2026-2167 | CVE-2026-2167 Totolink WA300 cstecgi.cgi setAPNetwork os command injection (EUVD-2026-5782) )
TOTOLINKのWA300 Firmwareにおける複数の脆弱性
https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-003516.html

Original

Totolink WA300 5.2cu.7112_B20190227 に脆弱性が検出されました。影響を受ける箇所はファイル /cgi-bin/cstecgi.cgi の関数 setAPNetwork です。引数 Ipaddr の操作により OS コマンドインジェクションが発生します。この攻撃はリモートから実行される可能性があります。エクスプロイトが既に公開されており、悪用される恐れがあります。

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
JVN iPedia
First Published:
2026-02-13
Source Information Category:
Advisory, Alert
Last Updated:
2026-02-13




Affected Product Tags
cpe:/o:totolink:wa300_firmware
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
X Single [?]
None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives
Common Vulnerabilities and Exposures (CVE) CVE-2026-2167




National Vulnerability Database (NVD) CVE-2026-2167




VulDB CVE-2026-2167 Totolink WA300 cstecgi.cgi setAPNetwork os command injection (EUVD-2026-5782)








References
Issues The TOTOLINK WA300 model has a remote command execution vulnerability in the "setting/setAPNetwork" interface. Issue #36 master-abc/cve




JVNDB CWE-77 コマンドインジェクション




JVNDB CWE-78 OSコマンドインジェクション




VulDB Submit #752063: TOTOLINK WA300 V5.2cu.7112_B20190227 OS Command Injection




関連文書 TOTOLINK





Copyright © 2026 JPCERT/CC All Rights Reserved.