Impact
The flaw is in the setNtpCfg function of the /cgi-bin/cstecgi.cgi CGI handler in Totolink A8000RU firmware. A maliciously crafted tz argument is passed directly to the operating system, permitting an attacker to execute arbitrary OS commands. This remote command injection grants full control over the device, compromising confidentiality, integrity, and availability.
Affected Systems
Totolink A8000RU routers running firmware version 7.1cu.643_b20200521 are affected. The vulnerable setNtpCfg function appears only in this firmware build of the A8000RU series.
Risk and Exploitability
The CVSS score of 9.3 classifies the issue as critical. An EPSS score of 3% indicates a moderate likelihood of exploitation. The vulnerability can be triggered from a remote, unauthenticated HTTP request; this inference comes from the described remote exploit and the absence of any authentication requirement in the description. Public exploit code is available, raising the risk of full device compromise, although the vulnerability is not listed in CISA KEV.
OpenCVE Enrichment