Impact
The flaw is in the setMiniuiHomeInfoShow handler of the /cgi-bin/cstecgi.cgi script in Totolink A7100RU firmware 7.4cu.2313_b20191024. An attacker who can supply a crafted lan_info argument can inject and execute arbitrary operating‑system commands on the device. This injection permits complete compromise of confidentiality, integrity, and availability by giving the attacker full control over the router and the possibility to extend attacks to the wider network.
Affected Systems
The vulnerability affects Totolink A7100RU models running firmware version 7.4cu.2313_b20191024. Only the CGI handler component is impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates the flaw is critical, and publicly available exploits have already been published. The attack can be launched remotely from the Internet. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The combination of a high severity score, known public exploits, and remote execution capability means the risk to unpatched devices is high.
OpenCVE Enrichment