OS Command Injection in Totolink A8000RU Web Management Interface
CVE-2026-9478
Key Information:
Badges
What is CVE-2026-9478?
A security weakness exists in the Totolink A8000RU's Web Management Interface related to the function 'setParentalRules' utilized in the '/cgi-bin/cstecgi.cgi' file. By manipulating the 'enable' argument, an attacker can perform OS command injection. This vulnerability allows for remote execution, exposing devices to potential unauthorized control. Publicly available exploits increase the risk of attacks, making it critical for users to secure their devices promptly.
Affected Version(s)
A8000RU 7.1cu.643_b20200521
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
