CVE-2026-1326: Totolink NR1800X POST Request cstecgi.cgi setWanCfg command injection
A weakness has been identified in Totolink NR1800X 9.1.0u.6279B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1326?
CVE-2026-1326 has been classified as a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-1326?
To mitigate CVE-2026-1326, update the Totolink NR1800X firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2026-1326?
CVE-2026-1326 specifically affects the Totolink NR1800X router running firmware version 9.1.0u.6279_B20210910.
What kind of attack can exploit CVE-2026-1326?
CVE-2026-1326 can be exploited through crafted POST requests that leverage command injection vulnerabilities.
Is CVE-2026-1326 remotely exploitable?
Yes, CVE-2026-1326 is remotely exploitable, allowing attackers to execute commands on the affected device without physical access.