CVE-2026-7037: Totolink A8000RU CGI cstecgi.cgi setVpnPassCfg os command injection
A security flaw has been discovered in Totolink A8000RU 7.1cu.643b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the Totolink A8000RU CGI Handler (/cgi-bin/cstecgi.cgi), since the os command injection can be executed remotely (e.g., block inbound access to the device from untrusted networks at the firewall/ACL).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7037?
CVE-2026-7037 is classified as a high-severity vulnerability due to the potential for OS command injection.
What devices are affected by CVE-2026-7037?
CVE-2026-7037 affects the Totolink A8000RU device running version 7.1cu.643_b20200521.
How can I mitigate CVE-2026-7037?
To mitigate CVE-2026-7037, it is recommended to upgrade the firmware of the Totolink A8000RU to a version that addresses this vulnerability.
What is the impact of exploiting CVE-2026-7037?
Exploitation of CVE-2026-7037 allows an attacker to execute arbitrary OS commands on the affected device.
How does CVE-2026-7037 exploit the vulnerable component?
CVE-2026-7037 exploits the 'setVpnPassCfg' function in the '/cgi-bin/cstecgi.cgi' file by manipulating the 'pptpPassThru' argument.