Impact
The vulnerability is an OS command injection in the setAccessDeviceCfg function of the cstecgi.cgi web management interface. An attacker can supply a crafted mac argument to execute arbitrary system commands on the router, effectively achieving remote code execution. Because the vulnerable code runs with the privileges of the web server, the attacker could gain full control over the device, enabling data exfiltration, configuration changes, or persistence.
Affected Systems
The flaw exists only in Totolink A8000RU routers running firmware version 7.1cu.643_b20200521. Earlier or newer versions are not known to be affected, but the absence of patch status in the advisory means the current firmware is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 denotes critical severity. EPSS score is not available but the exploit code has been released to the public, meaning it is freely available. The flaw is remotely exploitable through the web management interface, which is reachable from the internet. There is no KEV listing yet. Because the vulnerability provides full remote command execution, the overall risk is extremely high.
OpenCVE Enrichment