Impact
The vulnerability arises from the CsteSystem function in the /cgi-bin/cstecgi.cgi CGI handler on Totolink A8000RU routers. By manipulating the HTTP argument, an attacker can cause the system to execute arbitrary operating system commands. This flaw is an instance of CWE-77 and CWE-78 and provides remote code execution capabilities.
Affected Systems
The affected device is the Totolink A8000RU router running firmware version 7.1cu.643_b20200521. The flaw is present in the CGI handler component of the firmware, which can be accessed remotely over HTTP.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. With the exploit publicly available and no mitigation listed in KEV, attackers can readily target the device. The lack of an EPSS score means we cannot quantify precise exploitation probability, but the presence of a remote code execution vector and a public exploit suggests a high risk. Administrators should treat this as an urgent threat.
OpenCVE Enrichment