


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of…
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 02:02:55
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical OS command injection vulnerability (CVE-2026-7203) was discovered in Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability affects the setUrlFilterRules function in the CGI Handler component at /cgi-bin/cstecgi.cgi. Attackers can manipulate the 'enable' argument to execute arbitrary OS commands remotely. The exploit code has been publicly disclosed and is available on GitHub, making this vulnerability particularly dangerous for affected devices. This represents a significant security risk for network infrastructure as it allows remote code execution on networking equipment.
Technical details
Mitigation steps:
Affected products:
Totolink A8000RU
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7203
https://github.com/Litengzheng/vuldb_new2/blob/main/A8000RU/vul_322/README.md
https://vuldb.com/submit/801528
https://vuldb.com/vuln/359803
https://vuldb.com/vuln/359803/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
/cgi-bin/cstecgi.cgi
This article was created with the assistance of AI technology by Perceptive.
