CVE-2026-7139: Totolink A8000RU CGI cstecgi.cgi setWiFiAclRules os command injection
A flaw has been found in Totolink A8000RU 7.1cu.643b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mode causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7139?
CVE-2026-7139 has been identified as a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2026-7139?
To remediate CVE-2026-7139, apply the latest firmware update provided by Totolink for the A8000RU model.
What component is affected by CVE-2026-7139?
CVE-2026-7139 affects the CGI handler function setWiFiAclRules in the cstecgi.cgi file.
What types of attacks can CVE-2026-7139 enable?
CVE-2026-7139 can enable OS command injection attacks, allowing unauthorized commands to be executed on the device.
Which versions of the Totolink A8000RU are affected by CVE-2026-7139?
CVE-2026-7139 affects Totolink A8000RU version 7.1cu.643_b20200521.