Impact
A vulnerability is an OS command injection flaw located in the setMacFilterRules function of /cgi-bin/cstecgi.cgi within the Web Management Interface of the Totolink A8000RU router. An attacker who can supply crafted input to the enable argument can execute arbitrary shell commands on the device. Because the flaw lies in the web‑based administration component, the attacker can exploit it remotely without needing local access, satisfying a remote code execution risk.
Affected Systems
Affected systems are Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. No other versions or firmware revisions are explicitly listed as vulnerable, so only this build appears to be impacted. The router model A8000RU is a home and small‑office device distributed by Totolink.
Risk and Exploitability
The CVSS score of 9.3 places it in the Critical tier, and there is evidence that exploit code is publicly available. Although the EPSS metric has not been reported, the presence of publicly posted payloads and the lack of mitigation from the vendor raise the likelihood of exploitation. The flaw is not yet catalogued in CISA’s KEV, but that does not diminish the urgency; the remote attack vector and the ability to run arbitrary commands make it a high‑risk vulnerability.
OpenCVE Enrichment