


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cst…
Published:
26 April 2026 at 22:00:00
Alert date:
27 April 2026 at 21:01:41
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A critical security vulnerability has been identified in Totolink A8000RU router firmware version 7.1cu.643_b20200521. The flaw exists in the setMiniuiHomeInfoShow function within the CGI Handler component at /cgi-bin/cstecgi.cgi. Attackers can exploit this vulnerability by manipulating the sys_info argument to achieve OS command injection. The attack can be executed remotely, making it particularly dangerous. A public exploit has been released and is available for potential attackers to use. This vulnerability poses a significant risk to affected devices and networks.
Technical details
Mitigation steps:
Affected products:
Totolink A8000RU
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7153
https://github.com/Litengzheng/vuldb_new2/blob/main/A8000RU/vul_317/README.md
https://vuldb.com/submit/801139
https://vuldb.com/vuln/359752
https://vuldb.com/vuln/359752/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
