Description
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-05-25
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability is an OS command injection flaw located in the setMacFilterRules function of /cgi-bin/cstecgi.cgi within the Web Management Interface of the Totolink A8000RU router. An attacker who can supply crafted input to the enable argument can execute arbitrary shell commands on the device. Because the flaw lies in the web‑based administration component, the attacker can exploit it remotely without needing local access, satisfying a remote code execution risk.

Affected Systems

Affected systems are Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. No other versions or firmware revisions are explicitly listed as vulnerable, so only this build appears to be impacted. The router model A8000RU is a home and small‑office device distributed by Totolink.

Risk and Exploitability

The CVSS score of 9.3 places it in the Critical tier, and there is evidence that exploit code is publicly available. Although the EPSS metric has not been reported, the presence of publicly posted payloads and the lack of mitigation from the vendor raise the likelihood of exploitation. The flaw is not yet catalogued in CISA’s KEV, but that does not diminish the urgency; the remote attack vector and the ability to run arbitrary commands make it a high‑risk vulnerability.

Generated by OpenCVE AI on May 25, 2026 at 07:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Totolink that fixes the command injection issue.
  • Limit access to the router’s web management interface to the local network or a secured VPN; disable remote management if not needed.
  • Enable logging and monitor the device for abnormal command execution or unexplained traffic, and use a network firewall or web filter to block suspicious HTTP requests targeting cstecgi.cgi.

Generated by OpenCVE AI on May 25, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 25 May 2026 06:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-25T06:15:13.158Z

Reserved: 2026-05-24T07:07:24.592Z

Link: CVE-2026-9433

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T08:00:12Z

Weaknesses