Impact
A weakness in the Totolink A8000RU firmware 7.1cu.643_b20200521 allows an attacker to supply a manipulated ‘wanIdx’ argument to the setDmzCfg function in /cgi-bin/cstecgi.cgi, which can then be used to execute arbitrary operating‑system commands. This flaw is a classic command‑injection vulnerability (CWE‑77 and CWE‑78) and provides the attacker with full control over the device’s command line, potentially leading to compromise of the router, disclosure of network secrets, or further pivoting within the local network.
Affected Systems
The affected product is the Totolink A8000RU router. Firmware version 7.1cu.643_b20200521 is vulnerable; newer firmware revisions are not confirmed as fixed.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. No EPSS score is available, so the likelihood of exploitation cannot be quantified from the data, but an exploit has been made publicly available. The vulnerability can be triggered remotely by sending crafted requests to the router’s web interface. It is not clear from the CVE description whether authentication is required; the router’s management interface typically requires administrative credentials, but no explicit requirement is stated. The flaw is listed in no KEV catalog yet, so mitigations rely on vendor updates or network controls.
OpenCVE Enrichment