


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the compo…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 10:02:18
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A remote command injection vulnerability was discovered in Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability affects the setWiFiBasicCfg function in the CGI handler component at /cgi-bin/cstecgi.cgi. Attackers can exploit this by manipulating the wifiOff argument to inject OS commands. The vulnerability can be exploited remotely and public exploits are available, making it particularly dangerous for affected devices.
Technical details
Mitigation steps:
Affected products:
Totolink A8000RU
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7241
https://github.com/Litengzheng/vuldb_new2/blob/main/A8000RU/vul_325/README.md
https://vuldb.com/submit/803086
https://vuldb.com/vuln/359848
https://vuldb.com/vuln/359848/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
