Description
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.
Published: 2026-05-25
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the setOpenVpnCertGenerationCfg function of the Totolink A8000RU's cstecgi.cgi, where an attacker can manipulate the servername parameter to inject arbitrary OS commands. Because the service is exposed via the router's web interface, a remote attacker can issue any shell command with the privileges of the device, leading to full compromise of the router's firmware and the network it manages. The injection vulnerability falls under CWE-77 and CWE-78 and results in loss of confidentiality, integrity and availability of the device and connected resources.

Affected Systems

Affected devices are Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. No other versions have been confirmed to be impacted, but users should verify whether newer revisions contain the same flaw. The vulnerability is limited to the web management interface and specifically the cstecgi.cgi script handling OpenVPN certificate generation configuration.

Risk and Exploitability

The CVSS score of 9.3 reflects a critical impact, and the EPSS score is not reported, though public exploits have been released, indicating that attackers already have functioning attack code. The vulnerability is remotely exploitable via the router's web UI without authentication, so an adversary on the same network or with remote network access can trigger the injection. The absence of any CISA KEV listing does not reduce the threat because the flaw is widely known and actively used.

Generated by OpenCVE AI on May 25, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware upgrade from Totolink that patches the cstecgi.cgi command injection flaw.
  • Disable remote management or limit web interface access to trusted LAN subnets or IPs to prevent external exploitation.
  • If an immediate firmware update is not available, block access to the cstecgi.cgi endpoint or disable the OpenVPN certificate generation feature to eliminate the vulnerable parameter.

Generated by OpenCVE AI on May 25, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 25 May 2026 12:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.
Title Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-25T11:30:12.630Z

Reserved: 2026-05-24T07:57:17.463Z

Link: CVE-2026-9454

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T13:30:26Z

Weaknesses