Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-7153

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sys_info results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Ver en NVD

Análisis

This is a remote command injection vulnerability in a specific Totolink router model. While the severity is critical and an exploit is public, it targets niche consumer networking hardware that does not impact the software development or infrastructure tools used by the MexicoDev community.

Severidad

Puntaje: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-77CWE-78

EPSS

Probabilidad de explotación (próx. 30 días): 0.0125 (1.3%)
Percentil: 79.5%
EPSS: 2026-05-06

Descripción técnica

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sys_info results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Publicada: 27/4/2026, 20:16:29
Última modificación: 27/4/2026, 20:21:52

Referencias

InicioEventosBlogRecursosEquipo