Impact
The vulnerability resides in the CsteSystem function of the /cgi-bin/cstecgi.cgi CGI handler on Totolink A8000RU firmware 7.1cu.643_b20200521. By manipulating request arguments, an attacker can inject and execute operating‑system commands. A successful exploit enables remote execution of arbitrary commands, compromising the router’s confidentiality, integrity and availability.
Affected Systems
Affected systems are Totolink A8000RU routers running firmware 7.1cu.643_b20200521 or earlier versions that include the vulnerable CGI handler.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is considered critical. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the public disclosure and remote attack vector raise the likelihood of exploitation. Attackers can trigger the flaw over HTTP from outside the local network.
OpenCVE Enrichment