OS Command Injection Vulnerability in Totolink A8000RU Product
CVE-2026-7241
Key Information:
Badges
What is CVE-2026-7241?
A newly discovered vulnerability in the Totolink A8000RU affects the CGI handler's setWiFiBasicCfg function, allowing attackers to perform remote OS command injections. By manipulating the 'wifiOff' argument in the /cgi-bin/cstecgi.cgi file, unauthorized execution of commands could be executed, posing significant security risks to the device. Exploits for this vulnerability have already been made public, underlining the urgent need for users to implement security measures.
Affected Version(s)
A8000RU 7.1cu.643_b20200521
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
