Description
A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Problem types
Product status
Timeline
| 2026-01-29: | Advisory disclosed |
| 2026-01-29: | VulDB entry created |
| 2026-01-30: | VulDB entry last update |
Credits
xuanyu (VulDB User)
References
vuldb.com/?id.343382 (VDB-343382 | Totolink A7000R cstecgi.cgi setUpgradeFW command injection)
vuldb.com/?ctiid.343382 (VDB-343382 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.740767 (Submit #740767 | TOTOLINK A7000R V4.1cu.4154 Command Injection)
github.com/...ain/TOTOLINK/A7000R/04_RCE_setUpgradeFW_RCE.md
github.com/...ain/TOTOLINK/A7000R/04_RCE_setUpgradeFW_RCE.md
www.totolink.net/