Impact
A command injection flaw exists in the setVpnAccountCfg function of the /cgi-bin/cstecgi.cgi CGI handler on the Totolink A7100RU router. An attacker can inject arbitrary operating‑system commands through the User parameter, allowing remote execution of code on the device’s underlying firmware environment. The flaw is exploitable from outside the local network and is listed as publicly known, meaning reasonable attackers can craft and send a malicious request to trigger the vulnerability.
Affected Systems
The vulnerability affects Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024. Devices running any other firmware revision are not identified as affected in the given data.
Risk and Exploitability
The CVSS score of 9.3 designates the issue as critical in severity. An EPSS score of 3% suggests a moderate likelihood of exploitation in the current time window. The exploit is publicly available, but the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote, targeting the router’s publicly exposed CGI interface; no explicit authentication requirement is stated, so the assumption is that the request can be made without prior login.
OpenCVE Enrichment