CVE-2026-7243: Totolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection
A vulnerability was identified in Totolink A8000RU 7.1cu.643b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument maxRtrAdvInterval leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7243?
CVE-2026-7243 has a high severity rating due to its potential for os command injection.
How do I fix CVE-2026-7243?
To fix CVE-2026-7243, update your Totolink A8000RU firmware to the latest version provided by the manufacturer.
What products are affected by CVE-2026-7243?
The affected product for CVE-2026-7243 is the Totolink A8000RU with the firmware version 7.1cu.643_b20200521.
What type of vulnerability is CVE-2026-7243?
CVE-2026-7243 is an os command injection vulnerability found in the CGI Handler of the Totolink A8000RU.
What component is vulnerable in CVE-2026-7243?
The vulnerable component in CVE-2026-7243 is the setRadvdCfg function in the cstecgi.cgi file.