Description
A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument tz results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.
Published: 2026-04-27
Score: 9.3 Critical
EPSS: 3.3% Low
KEV: No
Impact: Remote code execution
Action: Patch Firmware
AI Analysis

Impact

The flaw is in the setNtpCfg function of the /cgi-bin/cstecgi.cgi CGI handler in Totolink A8000RU firmware. A maliciously crafted tz argument is passed directly to the operating system, permitting an attacker to execute arbitrary OS commands. This remote command injection grants full control over the device, compromising confidentiality, integrity, and availability.

Affected Systems

Totolink A8000RU routers running firmware version 7.1cu.643_b20200521 are affected. The vulnerable setNtpCfg function appears only in this firmware build of the A8000RU series.

Risk and Exploitability

The CVSS score of 9.3 classifies the issue as critical. An EPSS score of 3% indicates a moderate likelihood of exploitation. The vulnerability can be triggered from a remote, unauthenticated HTTP request; this inference comes from the described remote exploit and the absence of any authentication requirement in the description. Public exploit code is available, raising the risk of full device compromise, although the vulnerability is not listed in CISA KEV.

Generated by OpenCVE AI on September 26, 2026 at 09:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware release that patches the /cgi-bin/cstecgi.cgi setNtpCfg handler.
  • Limit external access to the /cgi-bin/cstecgi.cgi endpoint, permitting only trusted internal IP addresses.
  • If a firmware update cannot be applied, disable the NTP configuration feature or enforce strict input validation on the tz parameter to accept only permitted values.

Generated by OpenCVE AI on September 26, 2026 at 09:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 27 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument tz results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.
Title Totolink A8000RU CGI cstecgi.cgi setNtpCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T16:23:28.294Z

Reserved: 2026-04-26T19:30:08.560Z

Link: CVE-2026-7138

cve-icon Vulnrichment

Updated: 2026-04-27T16:23:22.159Z

cve-icon NVD

Status : Deferred

Published: 2026-04-27T16:16:47.283

Modified: 2026-06-17T11:01:54.320

Link: CVE-2026-7138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T09:30:11Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')