A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Metrics
Affected Vendors & Products
References
History
Thu, 29 Jan 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. | |
| Title | Totolink A7000R cstecgi.cgi setUpgradeFW command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-01-29T21:19:26.419Z
Reserved: 2026-01-29T14:39:06.213Z
Link: CVE-2026-1623
No data.
Status : Received
Published: 2026-01-29T21:15:53.427
Modified: 2026-01-29T21:15:53.427
Link: CVE-2026-1623
No data.
OpenCVE Enrichment
No data.