Command Injection Vulnerability in Totolink A8000RU Web Management Interface
CVE-2026-9405
Key Information:
Badges
What is CVE-2026-9405?
A vulnerability has been identified in the Totolink A8000RU router's web management interface, specifically within the setGameSpeedCfg function located in the cgi-bin/cstecgi.cgi file. This flaw allows an attacker to manipulate the argument 'enable', leading to the potential execution of arbitrary operating system commands. Remote exploitation is feasible, raising significant security concerns for affected users, especially since proof-of-concept exploits have been publicly released.
Affected Version(s)
A8000RU 7.1cu.643_b20200521
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
