Description
A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument url causes command injection. The attack can be initiated remotely. The exploit has been published and may be used.
Published: 2026-01-28
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Patch
AI Analysis

Impact

A command injection flaw is present in the CloudACMunualUpdateUserdata function of /cgi-bin/cstecgi.cgi on the Totolink A7000R. An attacker can send a crafted URL argument that causes the router to execute arbitrary shell commands. The CVE description states that the attack can be initiated remotely, but does not explicitly say whether authentication is required; it is inferred that the exposed web interface may be reachable without additional credentials.

Affected Systems

The vulnerability affects the Totolink A7000R model running firmware 4.1cu.4154. The CVE data does not list other firmware revisions as vulnerable, nor does it confirm that newer firmware releases contain a fix; this is inferred as unknown. Devices with the vulnerable firmware and a reachable remote management interface are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score shows a very low probability of exploitation (<1%). Nevertheless, a publicly available proof‑of‑concept exploit demonstrates that the flaw can be triggered remotely, making it a realistic threat for exposed routers. The vulnerability is not currently catalogued in the CISA KEV list. The attack vector is inferred to be remote exploitation via the web interface, exploiting the unchecked url parameter.

Generated by OpenCVE AI on April 18, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to the latest firmware that contains the fix for the CloudACMunualUpdateUserdata command injection.
  • If a patched firmware is unavailable, block remote access to /cgi-bin/cstecgi.cgi by configuring the router’s firewall or disabling the remote management interface.
  • Continuously monitor network traffic and system logs for anomalous activity involving the /cgi-bin/cstecgi.cgi endpoint, and promptly apply any vendor security advisories.

Generated by OpenCVE AI on April 18, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:totolink:a7000r_firmware:*:*:*:*:*:*:*:*

Mon, 09 Feb 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a7000r Firmware
CPEs cpe:2.3:h:totolink:a7000r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a7000r_firmware:4.1cu.4154:*:*:*:*:*:*:*
Vendors & Products Totolink a7000r Firmware

Thu, 29 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink a7000r
Vendors & Products Totolink
Totolink a7000r

Wed, 28 Jan 2026 22:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument url causes command injection. The attack can be initiated remotely. The exploit has been published and may be used.
Title Totolink A7000R cstecgi.cgi CloudACMunualUpdateUserdata command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A7000r A7000r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:02:35.766Z

Reserved: 2026-01-28T15:29:19.763Z

Link: CVE-2026-1548

cve-icon Vulnrichment

Updated: 2026-01-29T15:59:55.362Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-28T23:15:50.670

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-1548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T14:45:03Z

Weaknesses