CVE-2026-7204: Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection
A vulnerability was determined in Totolink A8000RU 7.1cu.643b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Totolink A8000RU CGI cstecgi.cgi setPptpServerCfgto a version that resolves this vulnerability.Fixed in 7.1cu.643_b20200521 - Compensating control
Restrict access to the Totolink A8000RU CGI endpoint (/cgi-bin/cstecgi.cgi) at the network level (e.g., firewall/ACL) to mitigate remotely initiated exploitation of setPptpServerCfg command injection.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7204?
CVE-2026-7204 has a medium severity rating due to its potential for OS command injection.
How do I fix CVE-2026-7204?
To fix CVE-2026-7204, update the Totolink A8000RU firmware to a version that addresses this vulnerability.
What is affected by CVE-2026-7204?
CVE-2026-7204 affects the Totolink A8000RU with firmware version 7.1cu.643_b20200521.
How does CVE-2026-7204 exploit work?
CVE-2026-7204 exploits a vulnerability in the setPptpServerCfg function by manipulating parameters to execute commands on the server.
Is CVE-2026-7204 being actively exploited?
There is currently no public information indicating that CVE-2026-7204 is being actively exploited, but it remains a risk if devices are not updated.