Impact
A flaw exists in the setMiniuiHomeInfoShow function of /cgi-bin/cstecgi.cgi. By manipulating the sys_info argument, an attacker can inject arbitrary operating‑system commands. Successful exploitation would give the attacker full control over the router, allowing the disclosure or modification of data, denial of service, and potentially compromising any networks the device manages.
Affected Systems
The vulnerability affects Totolink A8000RU routers running firmware 7.1cu.643_b20200521. The issue resides within the CGI Handler component, specifically the cstecgi.cgi script. No other vendor or product variants are indicated in the data.
Risk and Exploitability
The CVSS base score of 9.3 classifies the issue as critical. EPSS information is unavailable, but the presence of publicly released exploit code and the remote nature of the attack denote a high likelihood of real‑world exploitation. Although the vulnerability is not listed in the CISA KEV catalog, its severity, exposure level, and exploit availability place it in the highest risk tier for affected devices.
OpenCVE Enrichment