CVE-2026-0641: TOTOLINK WA300 cstecgi.cgi sub_401510 command injection
A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112B20190227. This vulnerability affects the function sub401510 of the file cstecgi.cgi. The manipulation of the argument UPLOADFILENAME leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0641?
CVE-2026-0641 has a critical severity level due to its potential for remote command injection.
How do I fix CVE-2026-0641?
To fix CVE-2026-0641, update the TOTOLINK WA300 device to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2026-0641?
CVE-2026-0641 is classified as a command injection vulnerability affecting the TOTOLINK WA300 device.
Can CVE-2026-0641 be exploited remotely?
Yes, CVE-2026-0641 can be exploited remotely by sending crafted requests that manipulate the UPLOAD_FILENAME argument.
Which devices are affected by CVE-2026-0641?
CVE-2026-0641 specifically affects the TOTOLINK WA300 device running firmware version 5.2cu.7112_B20190227.