Description
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.
Published: 2026-05-25
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the Totolink A8000RU router’s web management interface, specifically the setL2tpServerCfg function in the /cgi-bin/cstecgi.cgi script. The flaw allows a remote attacker to supply a crafted value for the enable parameter, which is then unsafely passed to the operating system shell. Because of this, an attacker can execute arbitrary system commands, effectively taking full control of the device’s operating system. The vulnerability is rated CVSS 9.3, indicating a high‑severeness impact on confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. No other versions are listed in the current disclosure, and the flaw is tied to the specific web‑management interface of this product line.

Risk and Exploitability

The exploit is accessible to remote actors and has already been published by external resources. The CVSS score of 9.3 classifies it as critical, while the lack of an EPSS score means the current probability of exploitation is unknown but potentially significant due to the availability of a public exploit. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector is remote and the command injection can be executed directly against the web interface, the risk remains high if the router remains on the network without mitigation.

Generated by OpenCVE AI on May 25, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that addresses the command‑injection flaw.
  • If no patch is available, disable the L2TP server feature or block all external access to /cgi-bin/cstecgi.cgi to eliminate the injection surface.
  • Restrict the web‑management interface to a trusted internal network or VPN, enforce strong authentication, and consider temporarily disabling L2TP while monitoring for suspicious activity.

Generated by OpenCVE AI on May 25, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 25 May 2026 08:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.
Title Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-25T07:00:25.325Z

Reserved: 2026-05-24T07:07:32.636Z

Link: CVE-2026-9436

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T09:30:21Z

Weaknesses