A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of...
Description
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument wscDisabled leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AI Analyst Comment
Remediation
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Totolink
PRODUCT: A8000RU
AFFECTED_VERSIONS: 7.1cu.643_b20200521
---END_METADATA---
Description Summary:
A remote OS command injection vulnerability in the Totolink A8000RU CGI handler allows attackers to execute arbitrary code via the wscDisabled argument.
Executive Summary:
A critical remote command injection vulnerability in the Totolink A8000RU router allows unauthenticated attackers to achieve full system compromise.
Vulnerability Details
CVE-ID: CVE-2026-7202
Affected Software: Totolink A8000RU
Affected Versions: 7.1cu.643_b20200521
Vulnerability: This is an OS command injection vulnerability within the
setWiFiWpsStartfunction of the/cgi-bin/cstecgi.cgihandler. The vulnerability permits an unauthenticated remote attacker to inject malicious system commands by manipulating thewscDisabledargument.Business Impact
The CVSS score of 9.8 reflects the extreme severity of this flaw, as it allows for complete unauthorized control over the networking device. Successful exploitation could lead to total loss of device integrity, interception of network traffic, and a pivot point for further lateral movement within the corporate or home network.
Remediation Plan
Immediate Action: Apply the latest firmware update provided by Totolink immediately to patch the affected CGI handler.
Proactive Monitoring: Monitor network traffic for unusual outbound connections from the router and inspect system logs for anomalous command execution patterns.
Compensating Controls: Deploy a Web Application Firewall (WAF) or intrusion prevention system (IPS) to block malicious requests targeting the
/cgi-bin/cstecgi.cgiendpoint.Exploitation Status
Public Exploit Available: Yes
Analyst Notes: As of Apr 28, 2026, public exploit code for this vulnerability is available and active exploitation is possible. Immediate patching is mandatory to prevent compromise.
Analyst Recommendation
Given the critical nature of this vulnerability and the availability of public exploits, organizations must prioritize patching the affected Totolink hardware. If an update is not immediately feasible, restrict management interface access to trusted administrative networks only.