OS Command Injection Vulnerability in Totolink A8000RU Web Management Interface
CVE-2026-9458
Key Information:
Badges
What is CVE-2026-9458?
A vulnerability has been discovered in the Totolink A8000RU router, specifically within the Web Management Interface's setWanCfg function in the cgi-bin/cstecgi.cgi file. This flaw allows for OS command injection through manipulated arguments, enabling potential attackers to execute arbitrary commands on the affected device from a remote location. Given that the exploit details are publicly accessible, it poses a significant risk to users who do not apply necessary mitigations and updates.
Affected Version(s)
A8000RU 7.1cu.643_b20200521
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
