CVE 9.3 CRITICAL

Totolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection_CVE-2026-7241

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

AI Analysis

OS command injection vulnerability in Totolink A8000RU via the setWiFiBasicCfg function in the cgi-bin/cstecgi.cgi file

Basic Information

ID CVE-2026-7241
Source VulDB
Published Apr 28, 2026 at 07:30

Affected Product

Vendor Totolink
Product A8000RU
Version 7.1cu.643_b20200521
Affected Versions Totolink A8000RU 7.1cu.643_b20200521

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Totolink
Product A8000RU
Version 7.1cu.643_b20200521

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.