OS Command Injection Vulnerability in Totolink A8000RU Web Management Interface
CVE-2026-9477
Key Information:
Badges
What is CVE-2026-9477?
A security flaw has been identified within the Totolink A8000RU's Web Management Interface, specifically in the function setAccessDeviceCfg of the cgi-bin/cstecgi.cgi file. This vulnerability allows an attacker to inject OS commands through crafted input related to the 'mac' argument. As the exploit is publicly available, it poses a significant risk as it can be executed remotely, potentially compromising the integrity and security of affected devices.
Affected Version(s)
A8000RU 7.1cu.643_b20200521
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
