Command Injection Vulnerability in Totolink NR1800X Router
CVE-2026-1326
Key Information:
Badges
What is CVE-2026-1326?
A vulnerability has been discovered in the Totolink NR1800X router, specifically within the setWanCfg function located in the /cgi-bin/cstecgi.cgi file. This issue allows for command injection through improper handling of the Hostname parameter, enabling remote attackers to execute malicious commands. The exploit is publicly available, which raises significant security concerns for users running the affected firmware version. It is strongly advised to update to the latest firmware to mitigate this risk.
Affected Version(s)
NR1800X 9.1.0u.6279_B20210910
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
