Description
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument telnet_enabled leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-04-26: | Advisory disclosed |
| 2026-04-26: | VulDB entry created |
| 2026-04-26: | VulDB entry last update |
Credits
LtzHuster2 (VulDB User)
References
vuldb.com/vuln/359751 (VDB-359751 | Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection)
vuldb.com/vuln/359751/cti (VDB-359751 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/801138 (Submit #801138 | Totolink A8000RU 7.1cu.643_b20200521 Command Injection)
github.com/...vuldb_new2/blob/main/A8000RU/vul_316/README.md
www.totolink.net/