CVE-2026-7122: Totolink A8000RU CGI cstecgi.cgi setUPnPCfg os command injection
A vulnerability has been found in Totolink A8000RU 7.1cu.643b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Totolink A8000RUto a version that resolves this vulnerability.Fixed in 7.1cu.643_b20200521 - Compensating control
Limit access to the remote management/interface that serves /cgi-bin/cstecgi.cgi (Totolink A8000RU CGI Handler) so the os command injection in setUPnPCfg cannot be triggered remotely.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7122?
CVE-2026-7122 is considered a critical vulnerability due to its potential to allow remote code execution through OS command injection.
How do I fix CVE-2026-7122?
To mitigate CVE-2026-7122, update the Totolink A8000RU to the latest firmware version that addresses this vulnerability.
What component is affected by CVE-2026-7122?
CVE-2026-7122 affects the CGI Handler component, specifically the setUPnPCfg function in the cstecgi.cgi file.
What type of attack can exploit CVE-2026-7122?
CVE-2026-7122 can be exploited through an OS command injection attack by manipulating the enable argument.
Which version of Totolink A8000RU is vulnerable to CVE-2026-7122?
Totolink A8000RU version 7.1cu.643_b20200521 is vulnerable to CVE-2026-7122.