
CVE-2026-31168 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the recHour parameter to /cgi-bin/cst… https://www.cve.org/CVERecord?id=CVE-2026-31168
Post summary
The CVE logs a command‑injection flaw in ToToLink A3300R firmware that permits arbitrary command execution via the recHour parameter; no exploit code, PoC, or patches are detailed.
