Description
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument command causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-05-23: | Advisory disclosed |
| 2026-05-23: | VulDB entry created |
| 2026-05-23: | VulDB entry last update |
Credits
LtzHuster (VulDB User)
References
vuldb.com/vuln/365348 (VDB-365348 | Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection)
vuldb.com/vuln/365348/cti (VDB-365348 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/813431 (Submit #813431 | Totolink A8000RU 7.1cu.643_b20200521 Command Injection)
github.com/...vuldb_new2/blob/main/A8000RU/vul_332/README.md
www.totolink.net/