Description
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Published: 2026-05-24
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw exists in the setDdnsCfg function of the /cgi-bin/cstecgi.cgi script used by the Totolink A8000RU Web Management Interface. By manipulating the arguments sent to this endpoint, an attacker can execute arbitrary operating‑system commands on the device. The vulnerability allows a remote attacker to run code with the privileges of the web server process, potentially compromising the entire router and any connected network. The CVE notes that the exploit is publicly available and that the attack can be launched remotely, indicating a high likelihood of exploitation in real‑world scenarios.

Affected Systems

This issue affects the Totolink A8000RU router running firmware version 7.1cu.643_b20200521. The vulnerability is tied to the Web Management Interface component and specifically targets the setDdnsCfg functionality within the cstecgi.cgi CGI script.

Risk and Exploitability

The CVSS score of 9.3 demonstrates a critical severity rating. EPSS information is not available, and the vulnerability is not currently listed in the CISA KEV catalog. However, the publicly available exploit together with the remote nature of the attack vector means that any exposed device is at substantial risk. An attacker simply needs to send a crafted HTTP request to /cgi-bin/cstecgi.cgi with a malicious setDdnsCfg payload; authentication or special permissions are not mentioned in the description, suggesting that the attack may be feasible from any network reachable to the router's management interface.

Generated by OpenCVE AI on May 25, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that addresses the command injection in the setDdnsCfg endpoint.
  • If a patch is unavailable, disable or block remote access to the Web Management Interface, or restrict it to a trusted internal network only.
  • For existing installations, block or remove the /cgi-bin/cstecgi.cgi CGI script from the web server's accessible paths to eliminate the vulnerable entry point.

Generated by OpenCVE AI on May 25, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Sun, 24 May 2026 23:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Title Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-24T23:00:24.401Z

Reserved: 2026-05-24T06:27:20.408Z

Link: CVE-2026-9404

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T01:00:06Z

Weaknesses