


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi o…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 19:18:12
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A vulnerability was identified in Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability affects the setWiFiEasyCfg function in the CGI Handler component, specifically in the /cgi-bin/cstecgi.cgi file. The issue allows for OS command injection through manipulation of the 'merge' argument. This vulnerability can be exploited remotely and public exploits are available. The attack vector targets the router's web interface through the CGI component, potentially allowing attackers to execute arbitrary system commands on the affected device.
Technical details
Mitigation steps:
Affected products:
Totolink A8000RU
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7125
https://github.com/Litengzheng/vuldb_new2/blob/main/A8000RU/vul_310/README.md
https://vuldb.com/submit/801006
https://vuldb.com/vuln/359724
https://vuldb.com/vuln/359724/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
/cgi-bin/cstecgi.cgi
This article was created with the assistance of AI technology by Perceptive.
