CVE-2026-7241: Totolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
A vulnerability was found in Totolink A8000RU 7.1cu.643b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7241?
CVE-2026-7241 is considered a critical vulnerability due to its potential for remote code execution via command injection.
How do I fix CVE-2026-7241?
To fix CVE-2026-7241, it is recommended to immediately update your Totolink A8000RU device to the latest firmware version provided by the vendor.
What are the consequences of exploiting CVE-2026-7241?
Exploiting CVE-2026-7241 can allow an attacker to execute arbitrary commands on the affected device, potentially compromising the entire network.
Which devices are affected by CVE-2026-7241?
CVE-2026-7241 affects the Totolink A8000RU router running version 7.1cu.643_b20200521.
What component is vulnerable in CVE-2026-7241?
The vulnerable component in CVE-2026-7241 is the CGI Handler, specifically the setWiFiBasicCfg function in the cstecgi.cgi file.