Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilityproof-of-concept-releaserapid-weaponizationinternet-facing-service-vulnerability

Critical Command Injection Flaws Expose Totolink A8000RU Routers to Remote RCE

Updated 2mo agoFirst seen Apr 27, 20264 sources

Three critical vulnerabilities, CVE-2026-7121, CVE-2026-7122, and CVE-2026-7125, were disclosed in the Totolink A8000RU router running firmware 7.1cu.643_b20200521, all affecting the /cgi-bin/cstecgi.cgi CGI handler. The flaws are OS command injection issues in the setWizardCfg, setUPnPCfg, and setWiFiEasyCfg functions, where crafted input to the wizard, enable, and merge arguments can trigger command execution on the device. The vulnerabilities are mapped to CWE-78 and CWE-77 and were rated critical across CVSS v2, CVSS v3.1, and CVSS v4.0 scoring schemes.

All three issues are remotely exploitable over the network and require no privileges and no user interaction, creating a high-risk exposure for internet-accessible devices. Public exploit information has already been disclosed, with references including VulDB entries and a GitHub proof-of-concept, increasing the likelihood of near-term exploitation. The disclosures indicate that multiple administrative configuration paths in the router's web interface can be abused for remote code execution, making unpatched A8000RU systems a priority for immediate review and remediation.

Share:
Critical Command Injection Flaws Expose Totolink A8000RU Routers to Remote RCE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Apr 27, 20262mo ago

CVE-2026-7152 published for Totolink A8000RU setTelnetCfg command injection

On 2026-04-27, a new CVE record, CVE-2026-7152, was published for a remotely exploitable OS command injection flaw in the setTelnetCfg function of /cgi-bin/cstecgi.cgi on Totolink A8000RU firmware 7.1cu.643_b20200521. The issue can be triggered via the telnet_enabled argument and public exploit information was reported as available.

CVE-2026-7152 - Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection

CVE-2026-7121, CVE-2026-7122, and CVE-2026-7125 entries were published

On April 27, 2026, new CVE records were published for three critical Totolink A8000RU vulnerabilities: CVE-2026-7121, CVE-2026-7122, and CVE-2026-7125. The entries classified the issues under CWE-77/CWE-78 and assigned critical severity across CVSS v2, v3.1, and v4.0.

Public exploits disclosed for three Totolink A8000RU command injection flaws

Public exploit information was available for three remotely exploitable OS command injection issues in Totolink A8000RU firmware 7.1cu.643_b20200521, affecting the setWizardCfg, setUPnPCfg, and setWiFiEasyCfg functions in /cgi-bin/cstecgi.cgi. The flaws require no privileges or user interaction and enable remote command execution via crafted CGI parameters.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical Command Injection Flaws Expose Totolink A8000RU Routers to Remote RCE | Mallory