Description
A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument sambaEnabled leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Published: 2026-04-27
Score: 9.3 Critical
EPSS: 1.3% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection flaw in the setStorageCfg function of the /cgi-bin/cstecgi.cgi CGI handler on Totolink A8000RU routers. By manipulating the sambaEnabled argument, an attacker can inject arbitrary shell commands that the device executes with elevated privileges. This allows full control over the router’s operating system, compromising confidentiality, integrity, and availability.

Affected Systems

The affected product is the Totolink A8000RU router running firmware version 7.1cu.643_b20200521. No other vendors or product variants are listed as impacted.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as Critical, and its remote nature enables exploitation over the network. The EPSS score is not available, and the vulnerability is not presently listed in CISA’s KEV catalog. An attacker can reach the vulnerable CGI endpoint by sending HTTP requests from an external host or by exploiting local network access, provided the router’s administration interface is exposed. Once exploited, the attacker can execute commands on the router’s operating system.

Generated by OpenCVE AI on April 28, 2026 at 04:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest release provided by Totolink that addresses the command‑injection issue.
  • If an update is unavailable, restrict external access to the /cgi-bin/cstecgi.cgi endpoint by applying firewall rules or network segmentation so only trusted local hosts can reach it.
  • Disable the Samba service or the sambaEnabled feature through router configuration or through firewall rules to eliminate the injection vector when immediate remediation is not possible.

Generated by OpenCVE AI on April 28, 2026 at 04:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument sambaEnabled leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Title Totolink A8000RU CGI cstecgi.cgi setStorageCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T17:57:52.595Z

Reserved: 2026-04-26T19:30:05.369Z

Link: CVE-2026-7137

cve-icon Vulnrichment

Updated: 2026-04-27T17:57:43.096Z

cve-icon NVD

Status : Deferred

Published: 2026-04-27T16:16:47.110

Modified: 2026-04-27T18:35:53.583

Link: CVE-2026-7137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T04:30:21Z

Weaknesses