Description
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Published: 2026-05-24
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Totolink A8000RU Web Management Interface permits an attacker to inject operating‑system commands through the setGameSpeedCfg CGI script by manipulating the enable parameter. The flaw is a classic OS command injection, allowing remote code execution with the privileges of the web service. The CVSS score of 9.3 indicates a critical level of severity. The vulnerability has been publicly disclosed and a proof‑of‑concept exploit has been released, confirming that exploitation is feasible without additional gaps.

Affected Systems

The affected device is the Totolink A8000RU router running firmware 7.1cu.643_b20200521. Users of this specific firmware revision are therefore exposed. No other versions are listed as impacted, but any device running the same firmware build should be considered at risk.

Risk and Exploitability

The CVSS score of 9.3 reflects the high likelihood of successful exploitation, and the lack of an EPSS value means no statistically derived probability is available. Because the attack can be performed remotely via the web interface, the attack vector is inferred to be remote. The vulnerability is not included in CISA’s KEV catalog, which suggests that widespread exploitation efforts may not yet be detected, but the public availability of an exploit indicates that attackers could act quickly.

Generated by OpenCVE AI on May 25, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that removes the vulnerable command binding.
  • If a firmware upgrade cannot be performed immediately, limit access to the Web Management Interface to trusted IP addresses or disable the interface altogether to prevent the CGI script from being reachable.
  • In the absence of a patch, enforce strict input validation on the enable parameter by allowing only the expected values and rejecting any other input; this mitigates the injection risk while a proper fix is deployed.

Generated by OpenCVE AI on May 25, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Sun, 24 May 2026 23:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Title Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-24T23:15:11.399Z

Reserved: 2026-05-24T06:27:22.764Z

Link: CVE-2026-9405

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T00:30:12Z

Weaknesses