CVE-2026-7823: Totolink A8000RU cstecgi.cgi setAppFilterCfg os command injection
A security flaw has been discovered in Totolink A8000RU 7.1cu.643b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7823?
CVE-2026-7823 is classified as a high-severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2026-7823?
To fix CVE-2026-7823, it is recommended to update the Totolink A8000RU to a version that addresses this vulnerability.
What are the potential impacts of CVE-2026-7823?
The potential impacts of CVE-2026-7823 include unauthorized access and execution of arbitrary commands on the affected device.
Who is affected by CVE-2026-7823?
CVE-2026-7823 affects users of the Totolink A8000RU version 7.1cu.643_b20200521.
What component of Totolink A8000RU is vulnerable in CVE-2026-7823?
The vulnerable component in CVE-2026-7823 is the function setAppFilterCfg of the cstecgi.cgi file.