Impact
A vulnerability exists in the setRadvdCfg function of the /cgi-bin/cstecgi.cgi CGI handler on the Totolink A8000RU router. By sending a crafted argument maxRtrAdvInterval, an attacker can inject operating system commands. This flaw allows the execution of arbitrary commands with the privileges of the web service, leading to compromise of confidentiality, integrity, and availability of the device and potentially the broader network.
Affected Systems
The affected product is the Totolink A8000RU router running firmware version 7.1cu.643_b20200521. No other vendors or product versions are listed in the CNA data for this CVE.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but publicly available exploits exist and may be actively used. The likely attack vector is remote, accessed via the router’s web interface; an attacker only needs to send a malicious HTTP request to the CGI endpoint to exploit the flaw.
OpenCVE Enrichment