Impact
The vulnerability is an OS command injection flaw in the CsteSystem CGI function of /cgi-bin/cstecgi.cgi on Totolink A7100RU routers. By manipulating the resetFlags argument, a remote attacker can inject arbitrary shell commands and potentially gain full control of the device, compromising both the router and any traffic it handles. The flaw is rooted in unsanitized input handling, typical of CWE‑77 and CWE‑78.
Affected Systems
Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024. No other firmware versions are indicated as affected in the available data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while an EPSS score of 1% reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack may be initiated remotely, the likely vector is a crafted HTTP request to /cgi-bin/cstecgi.cgi that injects malicious resetFlags values. The exploit is publicly released, so real‑world attacks are plausible on devices exposed to external networks.
OpenCVE Enrichment