A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument enabled leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument enabled leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Title | Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection | |
| First Time appeared |
Totolink
Totolink a8000ru Firmware |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink
Totolink a8000ru Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-25T12:30:13.344Z
Reserved: 2026-05-24T07:57:28.742Z
Link: CVE-2026-9458
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T14:45:16Z