Impact
A command injection flaw is present in the CloudACMunualUpdateUserdata function of /cgi-bin/cstecgi.cgi on the Totolink A7000R. An attacker can send a crafted URL argument that causes the router to execute arbitrary shell commands. The CVE description states that the attack can be initiated remotely, but does not explicitly say whether authentication is required; it is inferred that the exposed web interface may be reachable without additional credentials.
Affected Systems
The vulnerability affects the Totolink A7000R model running firmware 4.1cu.4154. The CVE data does not list other firmware revisions as vulnerable, nor does it confirm that newer firmware releases contain a fix; this is inferred as unknown. Devices with the vulnerable firmware and a reachable remote management interface are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score shows a very low probability of exploitation (<1%). Nevertheless, a publicly available proof‑of‑concept exploit demonstrates that the flaw can be triggered remotely, making it a realistic threat for exposed routers. The vulnerability is not currently catalogued in the CISA KEV list. The attack vector is inferred to be remote exploitation via the web interface, exploiting the unchecked url parameter.
OpenCVE Enrichment