Impact
A flaw in the setWizardCfg function of the /cgi-bin/cstecgi.cgi component allows remote manipulation of the wizard argument to inject and execute arbitrary operating system commands. This leads to complete compromise of the device’s control plane, granting an attacker full administrative privileges. The weakness aligns with OS command injection problems documented as CWE‑77 and CWE‑78.
Affected Systems
All Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024 are affected. The vulnerability is specific to the CGI Handler element present in these devices.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating critical severity. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, but a public exploit has been released, suggesting the attack vector is remote and exploitable over the network. An attacker can simply send a crafted request to the affected endpoint to execute arbitrary commands, with no local privileges required.
OpenCVE Enrichment