Impact
A weakness in Totolink A7100RU firmware allows OS command injection through the setUrlFilterRules function in /cgi-bin/cstecgi.cgi. The enable argument can be manipulated to execute arbitrary shell commands on the router, providing an attacker with full control. The description states that the attack can be launched remotely and that an exploit tool is publicly available, indicating that no local privilege or authentication is required to abuse the flaw.
Affected Systems
The vulnerability is documented for firmware version 7.4cu.2313_b20191024 of the Totolink A7100RU router. Other revisions are not explicitly confirmed or denied, so additional builds may also be affected unless they contain the patch identified in the vendor references.
Risk and Exploitability
The CVSS base score of 9.3 signals critical severity, while the EPSS score of 2% suggests a moderate likelihood of exploitation. The flaw is not listed in CISA KEV but its remote nature, high impact, availability of public exploitation code, and lack of authentication requirements create a compelling risk for any affected router.
OpenCVE Enrichment