CVE-2026-7140: Totolink A8000RU CGI cstecgi.cgi CsteSystem os command injection
A vulnerability has been found in Totolink A8000RU 7.1cu.643b20200521. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument HTTP leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7140?
The severity of CVE-2026-7140 is classified as high due to the potential for remote code execution through OS command injection.
How do I fix CVE-2026-7140?
To fix CVE-2026-7140, update the Totolink A8000RU firmware to a version that addresses this vulnerability.
What systems are affected by CVE-2026-7140?
CVE-2026-7140 affects the Totolink A8000RU with firmware version 7.1cu.643_b20200521.
What is the impact of CVE-2026-7140?
The impact of CVE-2026-7140 includes unauthorized execution of commands on the affected system, potentially leading to a complete takeover.
What component is vulnerable in CVE-2026-7140?
The component vulnerable in CVE-2026-7140 is the CGI Handler, specifically in the CsteSystem function of the cstecgi.cgi file.