CVE-2026-82597: TOTOLINK NR1800X cstecgi.cgi setUssd command injection
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attack can be initiated remotely, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
Which product version is known to be affected?
The reported affected version is TOTOLINK NR1800X 9.1.0u.6681_B20230703. The provided information does not establish whether earlier or later versions are affected.
How serious is exploitation?
Successful exploitation allows command injection through the ussd argument handled by the setUssd function in /cgi-bin/cstecgi.cgi. The reported impact includes low confidentiality, integrity, and availability effects, with scope changed.
Is exploit code available?
Yes. The vulnerability information states that a public exploit is available and might be used.