Description
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument resetFlags results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-05-24
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows an attacker to inject arbitrary operating‑system commands by manipulating the resetFlags parameter in the setUpgradeFW function of the cstecgi.cgi script. This remote OS command injection can be leveraged to execute any command with the privileges of the web management interface process, providing full control over the device and compromising confidentiality, integrity, and availability.

Affected Systems

Affected system is Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. Only this version was verified to be impacted; earlier firmware revisions may not be affected.

Risk and Exploitability

The CVSS score of 9.3 marks this as critical. No EPSS score is available, so exact exploitation probability is unknown, but the public release of the exploit and the ability to launch attacks remotely elevate the risk. The vulnerability is not listed in CISA KEV, yet the exposed web interface provides a feasible attack surface for remote adversaries. An attacker could remotely send crafted HTTP requests to the Web Management Interface from any machine that can reach the router.

Generated by OpenCVE AI on May 24, 2026 at 15:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to the latest firmware that resolves the OS command injection flaw.
  • If an update is not yet available, restrict the Web Management Interface to trusted networks by configuring firewall rules, VLAN isolation, or disabling remote management.
  • As a temporary workaround, block or rename the /cgi-bin/cstecgi.cgi endpoint or the setUpgradeFW function via the router's built‑in firewall or proxy settings to prevent external access.
  • Ensure that any input to the resetFlags parameter is validated and sanitized to prevent command injection by following vendor secure coding guidelines.

Generated by OpenCVE AI on May 24, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 24 May 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Sun, 24 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument resetFlags results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Title Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-24T14:15:09.998Z

Reserved: 2026-05-23T15:03:13.975Z

Link: CVE-2026-9387

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-24T15:30:02Z

Weaknesses