CVE-2026-1327: Totolink NR1800X POST Request cstecgi.cgi setTracerouteCfg command injection
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Such manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1327?
CVE-2026-1327 has been rated as a high severity vulnerability.
How do I fix CVE-2026-1327?
To fix CVE-2026-1327, update the Totolink NR1800X firmware to the latest version available from the manufacturer.
What does CVE-2026-1327 affect?
CVE-2026-1327 affects the setTracerouteCfg function in the /cgi-bin/cstecgi.cgi file of the Totolink NR1800X router.
What type of vulnerability is CVE-2026-1327?
CVE-2026-1327 is classified as a command injection vulnerability.
Is CVE-2026-1327 exploitable remotely?
Yes, CVE-2026-1327 can be exploited remotely without authentication.