Impact
The flaw allows an attacker to inject arbitrary operating‑system commands by manipulating the resetFlags parameter in the setUpgradeFW function of the cstecgi.cgi script. This remote OS command injection can be leveraged to execute any command with the privileges of the web management interface process, providing full control over the device and compromising confidentiality, integrity, and availability.
Affected Systems
Affected system is Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. Only this version was verified to be impacted; earlier firmware revisions may not be affected.
Risk and Exploitability
The CVSS score of 9.3 marks this as critical. No EPSS score is available, so exact exploitation probability is unknown, but the public release of the exploit and the ability to launch attacks remotely elevate the risk. The vulnerability is not listed in CISA KEV, yet the exposed web interface provides a feasible attack surface for remote adversaries. An attacker could remotely send crafted HTTP requests to the Web Management Interface from any machine that can reach the router.
OpenCVE Enrichment