Impact
A vulnerability in the setNtpCfg function of /cgi-bin/cstecgi.cgi allows attackers to craft a request with a malicious tz argument that the router passes directly to the operating system, enabling arbitrary command execution from a remote HTTP request. This flaw provides the ability to read or modify any system file, install back‑doors, or use the device as a launch point for further attacks. Because the vulnerability is triggered by an unauthenticated web request, it threatens confidentiality, integrity, and availability of the device and any networks connected through it.
Affected Systems
The flaw is present in Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. The affected product line is the A8000RU series, with the culprit CGI handler in the firmware release from May 2020.
Risk and Exploitability
The CVSS base score of 9.3 marks this as a critical vulnerability. Although no EPSS score is published, the public availability of exploits and the fact that the attack vector is remote and unauthenticated result in a high likelihood of exploitation. The area of impact spans the entire router device, and because the command is executed with the router’s system privileges, an attacker could acquire full control of the device. The vulnerability is not currently listed in the CISA KEV catalog, but the risk remains substantial.
OpenCVE Enrichment