OS Command Injection Vulnerability in Totolink A8000RU by Totolink
CVE-2026-7242
Key Information:
Badges
What is CVE-2026-7242?
A serious OS command injection vulnerability exists in the Totolink A8000RU router, specifically in the function setOpenVpnClientCfg within the CGI Handler at /cgi-bin/cstecgi.cgi. This flaw allows an attacker to exploit a manipulation of the 'enabled' argument, leading to potential remote code execution. The vulnerability has been publicly documented and poses a significant risk to the device's security, making it imperative for users to apply necessary patches and enhance their network defenses.
Affected Version(s)
A8000RU 7.1cu.643_b20200521
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
