Impact
A vulnerability in the Totolink A8000RU Web Management Interface permits an attacker to inject operating‑system commands through the setGameSpeedCfg CGI script by manipulating the enable parameter. The flaw is a classic OS command injection, allowing remote code execution with the privileges of the web service. The CVSS score of 9.3 indicates a critical level of severity. The vulnerability has been publicly disclosed and a proof‑of‑concept exploit has been released, confirming that exploitation is feasible without additional gaps.
Affected Systems
The affected device is the Totolink A8000RU router running firmware 7.1cu.643_b20200521. Users of this specific firmware revision are therefore exposed. No other versions are listed as impacted, but any device running the same firmware build should be considered at risk.
Risk and Exploitability
The CVSS score of 9.3 reflects the high likelihood of successful exploitation, and the lack of an EPSS value means no statistically derived probability is available. Because the attack can be performed remotely via the web interface, the attack vector is inferred to be remote. The vulnerability is not included in CISA’s KEV catalog, which suggests that widespread exploitation efforts may not yet be detected, but the public availability of an exploit indicates that attackers could act quickly.
OpenCVE Enrichment