Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pm9-cvfw-h6fv

Опубликовано: 28 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.9
CVSS3: 9.8

Описание

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

EPSS

Процентиль: 82%
0.02448
Низкий

8.9 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

EPSS

Процентиль: 82%
0.02448
Низкий

8.9 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-77