Impact
A flaw exists in the Totolink A8000RU router’s web management interface, specifically the setL2tpServerCfg function in the /cgi-bin/cstecgi.cgi script. The flaw allows a remote attacker to supply a crafted value for the enable parameter, which is then unsafely passed to the operating system shell. Because of this, an attacker can execute arbitrary system commands, effectively taking full control of the device’s operating system. The vulnerability is rated CVSS 9.3, indicating a high‑severeness impact on confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. No other versions are listed in the current disclosure, and the flaw is tied to the specific web‑management interface of this product line.
Risk and Exploitability
The exploit is accessible to remote actors and has already been published by external resources. The CVSS score of 9.3 classifies it as critical, while the lack of an EPSS score means the current probability of exploitation is unknown but potentially significant due to the availability of a public exploit. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector is remote and the command injection can be executed directly against the web interface, the risk remains high if the router remains on the network without mitigation.
OpenCVE Enrichment