Impact
The vulnerability resides in the setWiFiEasyCfg function of the /cgi-bin/cstecgi.cgi component on the Totolink A8000RU router. By manipulating the merge argument, an attacker can inject arbitrary operating‑system commands that are executed with administrative privileges on the device. This enables complete takeover of the router, allowing code execution, data exfiltration, or deployment of further attacks. The weakness is a classic command‑injection flaw, reflected in CWE‑77 and CWE‑78.
Affected Systems
Affected is the Totolink A8000RU router running firmware version 7.1cu.643_b20200521. No other products or firmware versions are listed as impacted in the available information.
Risk and Exploitability
With a CVSS score of 9.3 the severity is high; the EPSS score of less than 1% indicates a low exploitation probability, yet a publicly available exploit exists. The router’s web interface exposes /cgi-bin/cstecgi.cgi without input sanitization, so a remote attacker can send a crafted HTTP request. The likely attack vector is an unauthenticated HTTPS or HTTP request from an external or internal network. Because the vulnerability is not listed in the CISA KEV catalog, there is no official cataloged exploitation data, but the combination of high severity and immediate exploit availability warrants urgent mitigation.
OpenCVE Enrichment