Description
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-05-25
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS command injection in the setAccessDeviceCfg function of the cstecgi.cgi web management interface. An attacker can supply a crafted mac argument to execute arbitrary system commands on the router, effectively achieving remote code execution. Because the vulnerable code runs with the privileges of the web server, the attacker could gain full control over the device, enabling data exfiltration, configuration changes, or persistence.

Affected Systems

The flaw exists only in Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. Earlier or newer versions are not known to be affected, but the absence of patch status in the advisory means the current firmware is vulnerable.

Risk and Exploitability

The CVSS score of 9.3 denotes critical severity. EPSS score is not available but the exploit code has been released to the public, meaning it is freely available. The flaw is remotely exploitable through the web management interface, which is reachable from the internet. There is no KEV listing yet. Because the vulnerability provides full remote command execution, the overall risk is extremely high.

Generated by OpenCVE AI on May 25, 2026 at 19:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to the latest firmware supplied by Totolink that resolves the command injection vulnerability.
  • If a firmware update is not immediately available, limit the web management interface to trusted IP addresses or disable it entirely.
  • Employ network segmentation to isolate the router from critical infrastructure and monitor for suspicious activity such as unexpected outbound traffic.

Generated by OpenCVE AI on May 25, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 25 May 2026 18:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Title Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-26T13:03:41.207Z

Reserved: 2026-05-24T09:15:35.694Z

Link: CVE-2026-9477

cve-icon Vulnrichment

Updated: 2026-05-26T13:03:37.500Z

cve-icon NVD

Status : Received

Published: 2026-05-25T18:16:31.903

Modified: 2026-05-25T18:16:31.903

Link: CVE-2026-9477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T20:00:11Z

Weaknesses