Description
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Published: 2026-04-27
Score: 9.3 Critical
EPSS: 1.3% Low
KEV: No
Impact: Remote OS command execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the setWiFiEasyCfg function of the /cgi-bin/cstecgi.cgi component on the Totolink A8000RU router. By manipulating the merge argument, an attacker can inject arbitrary operating‑system commands that are executed with administrative privileges on the device. This enables complete takeover of the router, allowing code execution, data exfiltration, or deployment of further attacks. The weakness is a classic command‑injection flaw, reflected in CWE‑77 and CWE‑78.

Affected Systems

Affected is the Totolink A8000RU router running firmware version 7.1cu.643_b20200521. No other products or firmware versions are listed as impacted in the available information.

Risk and Exploitability

With a CVSS score of 9.3 the severity is high; the EPSS score of less than 1% indicates a low exploitation probability, yet a publicly available exploit exists. The router’s web interface exposes /cgi-bin/cstecgi.cgi without input sanitization, so a remote attacker can send a crafted HTTP request. The likely attack vector is an unauthenticated HTTPS or HTTP request from an external or internal network. Because the vulnerability is not listed in the CISA KEV catalog, there is no official cataloged exploitation data, but the combination of high severity and immediate exploit availability warrants urgent mitigation.

Generated by OpenCVE AI on April 28, 2026 at 23:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a newer firmware release from Totolink that removes the vulnerable cstecgi.cgi implementation (any version newer than 7.1cu.643_b20200521).
  • Block external access to the router’s management interface by configuring firewall rules to deny all traffic to /cgi-bin/* from the Internet and permit only trusted internal hosts.
  • Place the router on an isolated VLAN or behind a perimeter firewall that restricts management access to a narrow set of authorized devices.
  • If a firmware update is not immediately available, disable the web‑based management interface or remove the cgi-bin directory from the web root to eliminate the attack surface.

Generated by OpenCVE AI on April 28, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 27 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Title Totolink A8000RU CGI cstecgi.cgi setWiFiEasyCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T14:08:34.294Z

Reserved: 2026-04-26T19:13:09.171Z

Link: CVE-2026-7125

cve-icon Vulnrichment

Updated: 2026-04-27T14:08:29.240Z

cve-icon NVD

Status : Deferred

Published: 2026-04-27T13:16:05.013

Modified: 2026-04-27T18:36:42.937

Link: CVE-2026-7125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T23:30:06Z

Weaknesses