Impact
The vulnerability allows an attacker to inject arbitrary operating system commands through the maxRtrAdvInterval parameter of the setRadvdCfg function in the cstecgi.cgi CGI handler. This results in remote OS command execution and full compromise of the affected router, giving the attacker control of the device. Based on the router's role, this control could extend to networks configured via the router, but that expansion is inferred from typical router behavior and is not explicitly stated in the disclosure.
Affected Systems
Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024 are affected. No other versions or products are listed as vulnerable in the available data.
Risk and Exploitability
The flaw scores a CVSS of 9.3, indicating critical severity. EPSS is 3%, suggesting a moderate exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. Attackers can initiate the exploit remotely by sending a crafted request to the /cgi-bin/cstecgi.cgi endpoint with a malicious maxRtrAdvInterval parameter. The likely attack vector is therefore remote network traffic; this inference is based on the description that the exploit can be initiated remotely. Successful exploitation results in remote OS command execution, leading to complete loss of confidentiality, integrity, and availability of the affected device.
OpenCVE Enrichment