CVE-2026-7154: Totolink A8000RU CGI cstecgi.cgi setAdvancedInfoShow os command injection
A weakness has been identified in Totolink A8000RU 7.1cu.643b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument ttyserver can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7154?
CVE-2026-7154 is considered high severity due to its potential for OS command injection.
How do I fix CVE-2026-7154?
To mitigate CVE-2026-7154, update the Totolink A8000RU firmware to the latest version.
What versions are affected by CVE-2026-7154?
CVE-2026-7154 affects the Totolink A8000RU version 7.1cu.643_b20200521.
What is the impact of CVE-2026-7154?
Exploitation of CVE-2026-7154 can allow an attacker to execute arbitrary OS commands on the affected device.
Is there a workaround for CVE-2026-7154?
As of now, the recommended action is to update the firmware, as there are no known workarounds.