CVE-2026-7153: Totolink A8000RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection
A security flaw has been discovered in Totolink A8000RU 7.1cu.643b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sysinfo results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7153?
CVE-2026-7153 is considered to have high severity due to its potential for remote code execution via OS command injection.
How do I fix CVE-2026-7153?
To mitigate CVE-2026-7153, update the Totolink A8000RU to the latest firmware version recommended by the vendor.
What products are affected by CVE-2026-7153?
The affected product is the Totolink A8000RU specifically on version 7.1cu.643_b20200521.
What type of vulnerability is CVE-2026-7153?
CVE-2026-7153 is an OS command injection vulnerability found in the CGI handler of the Totolink A8000RU.
Can CVE-2026-7153 be exploited remotely?
Yes, CVE-2026-7153 can be exploited remotely, allowing attackers to execute commands on the affected device.