Command Injection Vulnerability in Totolink A8000RU by Totolink
CVE-2026-7244
Key Information:
Badges
What is CVE-2026-7244?
A security flaw has been identified in the Totolink A8000RU router, specifically in the CGI Handler's setWiFiEasyGuestCfg function within the /cgi-bin/cstecgi.cgi file. This vulnerability allows an attacker to manipulate the merge argument, leading to os command injection. Such an exploit can be executed remotely, posing a significant risk as it has been made publicly available, enabling potential attackers to leverage this weakness for unauthorized access or control.
Affected Version(s)
A8000RU 7.1cu.643_b20200521
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
