


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the…
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 21:20:20
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A vulnerability was discovered in Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability affects the setPptpServerCfg function in the CGI Handler component, specifically in the /cgi-bin/cstecgi.cgi file. An attacker can manipulate the 'enable' argument to perform OS command injection attacks. The vulnerability can be exploited remotely and the exploit code has been publicly disclosed, making it readily available to attackers. This represents a significant security risk for affected Totolink router devices.
Technical details
Mitigation steps:
Affected products:
Totolink A8000RU
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7204
https://github.com/Litengzheng/vuldb_new2/blob/main/A8000RU/vul_323/README.md
https://vuldb.com/submit/801530
https://vuldb.com/vuln/359804
https://vuldb.com/vuln/359804/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
