CVE 9.3 CRITICAL

Totolink A8000RU CGI cstecgi.cgi setOpenVpnClientCfg os command injection_CVE-2026-7242

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enabled can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

AI Analysis

OS command injection vulnerability in Totolink A8000RU via manipulation of the 'enabled' argument in the setOpenVpnClientCfg function of the /cgi-bin/cstecgi.cgi file, allowing remote attackers to execute arbitrary commands.

Basic Information

ID CVE-2026-7242
Source VulDB
Published Apr 28, 2026 at 07:45

Affected Product

Vendor Totolink
Product A8000RU
Version 7.1cu.643_b20200521
Affected Versions Totolink A8000RU 7.1cu.643_b20200521

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Totolink
Product A8000RU
Version 7.1cu.643_b20200521

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.