Description
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Published: 2026-05-25
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A critical vulnerability was discovered in the Web Management Interface of the Totolink A8000RU router. The setParentalRules call within /cgi-bin/cstecgi.cgi can be abused by manipulating the enable parameter to inject arbitrary operating system commands. This flaw allows an attacker to execute commands with the privileges of the web server process, potentially compromising the entire device and any connected network infrastructure. The weakness is classed as CWE-77 and CWE-78, representing command injection due to improper validation of user-supplied input.

Affected Systems

The vulnerability impacts devices running the A8000RU firmware 7.1cu.643_b20200521 as released by Totolink. Only this specific firmware version is confirmed affected; newer releases are not listed, but operators should verify their firmware version.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity with remote exploits possible. EPSS is not available, but the public availability of an exploit demonstrates the likelihood of use. The vulnerability is not currently listed in the CISA KEV catalog, but the presence of a working exploit suggests that attackers could target exposed routers without requiring advanced skills. The attack vector is remote, relying on unauthenticated or limited authenticated HTTP requests to the device's web interface.

Generated by OpenCVE AI on May 25, 2026 at 19:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update that fixes the cstecgi.cgi command injection flaw
  • If an update is not immediately available, block external access to the router’s web management interface (typically ports 80 and 443) using a firewall or by disabling remote administration in the router settings
  • Where possible, enable network segmentation to isolate the router from critical infrastructure, ensuring that even if the device is compromised, lateral movement is constrained

Generated by OpenCVE AI on May 25, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a8000ru
Vendors & Products Totolink a8000ru

Mon, 25 May 2026 18:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Title Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection
First Time appeared Totolink
Totolink a8000ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a8000ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A8000ru A8000ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-25T17:30:11.752Z

Reserved: 2026-05-24T09:15:38.784Z

Link: CVE-2026-9478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-25T18:16:32.850

Modified: 2026-05-25T18:16:32.850

Link: CVE-2026-9478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T19:30:16Z

Weaknesses