Impact
The vulnerability resides in the setWiFiAclRules function of the /cgi-bin/cstecgi.cgi CGI handler. Manipulation of the "mode" argument allows an attacker to inject arbitrary operating‑system commands, leading to full remote code execution on the affected router. The description does not explicitly state the impact on confidentiality, integrity, or availability, but it is inferred that an attacker who gains control could potentially compromise the device’s confidentiality, integrity, and availability, as control over the device could enable configuration changes or use of the router as a foothold into the local network.
Affected Systems
The flaw affects Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. No other versions or product variants have been documented as impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score of 3% indicates a relatively low probability of exploitation, but the vulnerability is actively exploited as the exploit has been publicly released, and the document notes that the attack can be carried out remotely. Based on the description, it is inferred that the flaw is exposed through a publicly reachable CGI endpoint and that no authentication is required for the vulnerable parameter, meaning that any remote host with network access to the router could potentially trigger command injection and take full control of the device. Based on the fact that exploitation is demonstrated in the wild, it is inferred that the lack of a KEV listing does not diminish the risk.
OpenCVE Enrichment