Remote Command Injection in TOTOLINK NR1800X Device
CVE-2026-82597
Key Information:
Badges
What is CVE-2026-82597?
A remote command injection vulnerability exists in the TOTOLINK NR1800X that affects the setUssd function within the cgi-bin/cstecgi.cgi file. By manipulating the ussd argument, an attacker can execute unauthorized commands on the device, potentially compromising network security. As the exploit is publicly available, it poses a significant risk to users of this firmware version. It is recommended to update the device software urgently to mitigate this security threat.
Affected Version(s)
NR1800X 9.1.0u.6681_B20230703
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
