9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enabled can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
AI Analysis
OS command injection vulnerability in Totolink A8000RU via manipulation of the 'enabled' argument in the setOpenVpnClientCfg function of the /cgi-bin/cstecgi.cgi file, allowing remote attackers to execute arbitrary commands.
Basic Information
ID
CVE-2026-7242
Source
VulDB
Published
Apr 28, 2026 at 07:45
Affected Product
Vendor
Totolink
Product
A8000RU
Version
7.1cu.643_b20200521
Affected Versions
Totolink A8000RU 7.1cu.643_b20200521
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Totolink
Product
A8000RU
Version
7.1cu.643_b20200521