An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the sambaEnabled parameter in the setStora...
Description
An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the sambaEnabled parameter in the setStorageCfg function.
AI Analyst Comment
Remediation
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Totolink
PRODUCT: A8000RU
AFFECTED_VERSIONS: 7.1cu.643_b20200521
---END_METADATA---
Description Summary:
An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the sambaEnabled parameter in the setStorageCfg function.
Executive Summary:
A critical OS command injection vulnerability in the Totolink A8000RU router allows unauthenticated remote attackers to execute arbitrary commands.
Vulnerability Details
CVE-ID: CVE-2026-7137
Affected Software: Totolink A8000RU
Affected Versions: 7.1cu.643_b20200521
Vulnerability: This vulnerability occurs in the
setStorageCfgfunction within/cgi-bin/cstecgi.cgidue to insufficient sanitization of thesambaEnabledparameter, enabling remote OS command injection.Business Impact
The flaw grants an attacker full control over the router, which can lead to data breaches or network-wide compromise. The 9.8 CVSS score emphasizes the severity of this risk.
Remediation Plan
Immediate Action: Update to the latest firmware version and disable Samba/storage sharing features if they are not necessary.
Proactive Monitoring: Review system logs for unexpected system-level command execution.
Compensating Controls: Use a firewall to restrict access to the device's management interface.
Exploitation Status
Public Exploit Available: Yes
Analyst Notes: As of April 27, 2026, a public exploit is available for this vulnerability.
Analyst Recommendation
Urgent firmware updates are necessary to secure the device. If an update is not immediately available, disable all unnecessary features and restrict external access to the device.