Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-7538

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument proto leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

View on NVD

Analysis

This is a command injection vulnerability in a specific model of Totolink consumer router hardware. It matches the description of vendor-specific firmware that is not part of the standard web or mobile development stack used by the community.

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-77CWE-78

EPSS

Probability of exploitation (next 30 days): 0.0089 (0.9%)
Percentile: 75.6%
EPSS: 2026-05-06

Technical description

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument proto leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

Published: 5/1/2026, 2:16:04 AM
Last modified: 5/1/2026, 3:26:24 PM

References

HomeEventsBlogResourcesTeam