Impact
A critical vulnerability was discovered in the Web Management Interface of the Totolink A8000RU router. The setParentalRules call within /cgi-bin/cstecgi.cgi can be abused by manipulating the enable parameter to inject arbitrary operating system commands. This flaw allows an attacker to execute commands with the privileges of the web server process, potentially compromising the entire device and any connected network infrastructure. The weakness is classed as CWE-77 and CWE-78, representing command injection due to improper validation of user-supplied input.
Affected Systems
The vulnerability impacts devices running the A8000RU firmware 7.1cu.643_b20200521 as released by Totolink. Only this specific firmware version is confirmed affected; newer releases are not listed, but operators should verify their firmware version.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity with remote exploits possible. EPSS is not available, but the public availability of an exploit demonstrates the likelihood of use. The vulnerability is not currently listed in the CISA KEV catalog, but the presence of a working exploit suggests that attackers could target exposed routers without requiring advanced skills. The attack vector is remote, relying on unauthenticated or limited authenticated HTTP requests to the device's web interface.
OpenCVE Enrichment