Impact
The vulnerability is an OS command injection flaw in the setStorageCfg function of the /cgi-bin/cstecgi.cgi CGI handler on Totolink A8000RU routers. By manipulating the sambaEnabled argument, an attacker can inject arbitrary shell commands that the device executes with elevated privileges. This allows full control over the router’s operating system, compromising confidentiality, integrity, and availability.
Affected Systems
The affected product is the Totolink A8000RU router running firmware version 7.1cu.643_b20200521. No other vendors or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as Critical, and its remote nature enables exploitation over the network. The EPSS score is not available, and the vulnerability is not presently listed in CISA’s KEV catalog. An attacker can reach the vulnerable CGI endpoint by sending HTTP requests from an external host or by exploiting local network access, provided the router’s administration interface is exposed. Once exploited, the attacker can execute commands on the router’s operating system.
OpenCVE Enrichment