


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the…
Published:
26 April 2026 at 22:00:00
Alert date:
27 April 2026 at 19:18:12
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A critical vulnerability has been identified in Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability exists in the setDmzCfg function within the CGI handler component at /cgi-bin/cstecgi.cgi. An attacker can manipulate the wanIdx argument to achieve OS command injection. The vulnerability can be exploited remotely, making it particularly dangerous. Public exploits are already available, increasing the risk of active exploitation. This affects the router's web interface and could allow attackers to execute arbitrary commands on the device.
Technical details
Mitigation steps:
Affected products:
Totolink A8000RU
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7136
https://github.com/Litengzheng/vuldb_new2/blob/main/A8000RU/vul_311/README.md
https://vuldb.com/submit/801007
https://vuldb.com/vuln/359735
https://vuldb.com/vuln/359735/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
