Impact
A command injection flaw exists in the setFirewallType routine of the /cgi-bin/cstecgi.cgi script on Totolink A7100RU routers. By manipulating the firewallType parameter, an attacker can inject arbitrary shell commands that the router executes with system privileges. This vulnerability, corresponding to CWE‑77 and CWE‑78, allows the attacker to take complete control over the device’s operating system, potentially compromising network traffic, device configuration, and any data passing through the router.
Affected Systems
The affected product is the Totolink A7100RU router running firmware version 7.4cu.2313_b20191024. No other firmware revisions are mentioned, so only this specific build is confirmed to be vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 score of 6.9, indicating medium severity. The EPSS score of 1% reflects a very low but non‑zero chance of exploitation, and it is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a crafted HTTP request to the cstecgi.cgi endpoint; no additional credentials or privileged access are required. Because the attack can be performed without local access, the risk remains significant for devices exposed to untrusted networks.
OpenCVE Enrichment