Description
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wanIdx can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-04-27
Score: 9.3 Critical
EPSS: 1.3% Low
KEV: No
Impact: Remote OS Command Injection
Action: Patch immediately
AI Analysis

Impact

A weakness in the Totolink A8000RU firmware 7.1cu.643_b20200521 allows an attacker to supply a manipulated ‘wanIdx’ argument to the setDmzCfg function in /cgi-bin/cstecgi.cgi, which can then be used to execute arbitrary operating‑system commands. This flaw is a classic command‑injection vulnerability (CWE‑77 and CWE‑78) and provides the attacker with full control over the device’s command line, potentially leading to compromise of the router, disclosure of network secrets, or further pivoting within the local network.

Affected Systems

The affected product is the Totolink A8000RU router. Firmware version 7.1cu.643_b20200521 is vulnerable; newer firmware revisions are not confirmed as fixed.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. No EPSS score is available, so the likelihood of exploitation cannot be quantified from the data, but an exploit has been made publicly available. The vulnerability can be triggered remotely by sending crafted requests to the router’s web interface. It is not clear from the CVE description whether authentication is required; the router’s management interface typically requires administrative credentials, but no explicit requirement is stated. The flaw is listed in no KEV catalog yet, so mitigations rely on vendor updates or network controls.

Generated by OpenCVE AI on April 28, 2026 at 12:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the Totolink A8000RU that eliminates the setDmzCfg command‑injection flaw.
  • If an update is unavailable, enforce network‑level controls to restrict access to /cgi-bin/cstecgi.cgi to trusted management IPs only, using firewall or ACL rules.
  • As a temporary measure, disable the DMZ configuration feature in the router’s settings to prevent misuse of the vulnerable ‘wanIdx’ parameter.

Generated by OpenCVE AI on April 28, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 27 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wanIdx can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A8000RU CGI cstecgi.cgi setDmzCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T20:12:06.623Z

Reserved: 2026-04-26T19:30:01.226Z

Link: CVE-2026-7136

cve-icon Vulnrichment

Updated: 2026-04-27T19:32:29.952Z

cve-icon NVD

Status : Deferred

Published: 2026-04-27T16:16:46.930

Modified: 2026-04-27T18:35:53.583

Link: CVE-2026-7136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T13:00:15Z

Weaknesses