Three critical vulnerabilities, CVE-2026-7121, CVE-2026-7122, and CVE-2026-7125, were disclosed in the Totolink A8000RU router running firmware 7.1cu.643_b20200521, all affecting the /cgi-bin/cstecgi.cgi CGI handler. The flaws are OS command injection issues in the setWizardCfg, setUPnPCfg, and setWiFiEasyCfg functions, where crafted input to the wizard, enable, and merge arguments can trigger command execution on the device. The vulnerabilities are mapped to CWE-78 and CWE-77 and were rated critical across CVSS v2, CVSS v3.1, and CVSS v4.0 scoring schemes.
All three issues are remotely exploitable over the network and require no privileges and no user interaction, creating a high-risk exposure for internet-accessible devices. Public exploit information has already been disclosed, with references including VulDB entries and a GitHub proof-of-concept, increasing the likelihood of near-term exploitation. The disclosures indicate that multiple administrative configuration paths in the router's web interface can be abused for remote code execution, making unpatched A8000RU systems a priority for immediate review and remediation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-27, a new CVE record, CVE-2026-7152, was published for a remotely exploitable OS command injection flaw in the setTelnetCfg function of /cgi-bin/cstecgi.cgi on Totolink A8000RU firmware 7.1cu.643_b20200521. The issue can be triggered via the telnet_enabled argument and public exploit information was reported as available.
On April 27, 2026, new CVE records were published for three critical Totolink A8000RU vulnerabilities: CVE-2026-7121, CVE-2026-7122, and CVE-2026-7125. The entries classified the issues under CWE-77/CWE-78 and assigned critical severity across CVSS v2, v3.1, and v4.0.
Public exploit information was available for three remotely exploitable OS command injection issues in Totolink A8000RU firmware 7.1cu.643_b20200521, affecting the setWizardCfg, setUPnPCfg, and setWiFiEasyCfg functions in /cgi-bin/cstecgi.cgi. The flaws require no privileges or user interaction and enable remote command execution via crafted CGI parameters.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.