Impact
The vulnerability resides in the setUpgradeFW function within the cstecgi.cgi file of the Totolink A7000R firmware. By manipulating the FileName argument, an attacker can inject arbitrary shell commands, leading to remote execution of commands on the router and compromising confidentiality, integrity, and availability. The weakness maps to command injection flaws and can be triggered from outside the device via HTTP requests.
Affected Systems
Affected devices are Totolink A7000R routers running firmware version 4.1cu.4154. The vulnerability is present in the /cgi-bin/cstecgi.cgi component handling firmware upgrades. No other versions or products are listed; users of this exact model and firmware should verify the build before addressing the issue.
Risk and Exploitability
The CVSS base score is 5.3, indicating a medium-level severity. The EPSS probability of exploitation is 2 %, suggesting that while the vulnerability is not currently widely abused, it remains exploitable. The vulnerability is not yet identified in the CISA KEV catalog. Attackers could trigger it by remotely sending a crafted HTTP POST request to the setUpgradeFW endpoint, so the attack vector is network remote through the web interface. Given the potential for remote code execution, the risk to a connected network is significant.
OpenCVE Enrichment