CVE-2026-7203: Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection
A vulnerability was found in Totolink A8000RU 7.1cu.643b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Totolink A8000RUto a version that resolves this vulnerability.Fixed in 7.1cu.643_b20200521 - Compensating control
Mitigate the remotely exploitable CGI Handler vulnerability in /cgi-bin/cstecgi.cgi by restricting network access to the device/CGI endpoint from untrusted sources (e.g., block access at firewall/ACL/WAF).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7203?
CVE-2026-7203 is classified as a high severity vulnerability due to its potential for exploitation through OS command injection.
How do I fix CVE-2026-7203?
To mitigate CVE-2026-7203, update the Totolink A8000RU firmware to the latest version provided by the vendor.
What systems are affected by CVE-2026-7203?
CVE-2026-7203 affects the Totolink A8000RU device running firmware version 7.1cu.643_b20200521.
What is the impact of CVE-2026-7203?
Exploitation of CVE-2026-7203 could allow an attacker to execute arbitrary OS commands on the affected device.
Is CVE-2026-7203 being actively exploited?
As of now, there are no public reports indicating active exploitation of CVE-2026-7203.