In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.
| Software | From | Fixed in |
|---|---|---|
| totolink / a3300r_firmware | 17.0.0cu.557_b20221024 | 17.0.0cu.557_b20221024.x |