Impact
Based on the description, the flaw resides in the setPasswordCfg method of /cgi-bin/cstecgi.cgi used by Totolink A7100RU routers. By tampering with the admpass parameter, an attacker can inject arbitrary operating‑system commands, which the device executes. The description indicates that this injection results in unauthorized command execution; it is inferred that the attacker gains full device control, enabling configuration changes, data exfiltration, or service disruption, which compromises confidentiality, integrity, and availability.
Affected Systems
Based on the description, affected devices are Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024. The vulnerability exists in the setPasswordCfg CGI endpoint, meaning any router with this firmware is potentially susceptible.
Risk and Exploitability
Based on the description, the vulnerability carries a CVSS score of 9.3, indicating a critical rating, and an EPSS score of 14%, suggesting a moderate probability of exploitation. It is inferred that an attacker can trigger the injection without needing special privileges. The likely attack vector involves sending a remote HTTP request to the cstecgi.cgi endpoint from any network that can reach the router’s management interface. The issue is not yet listed in the CISA KEV catalog, which does not reduce the risk.
OpenCVE Enrichment