CVE-2026-9387: Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection
A security flaw has been discovered in Totolink A8000RU 7.1cu.643b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument resetFlags results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the Totolink A8000RU Web Management Interface (including /cgi-bin/cstecgi.cgi) so the os command injection via setUpgradeFW cannot be initiated remotely.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9387?
CVE-2026-9387 has a critical severity rating of 9.8.
How do I fix CVE-2026-9387?
To fix CVE-2026-9387, update the Totolink A8000RU firmware to the latest version that addresses this vulnerability.
What types of systems are affected by CVE-2026-9387?
CVE-2026-9387 affects the Totolink A8000RU router specifically.
What kind of vulnerability is CVE-2026-9387?
CVE-2026-9387 is an OS command injection vulnerability that allows unauthorized command execution.
What impact does CVE-2026-9387 have on security?
CVE-2026-9387 can lead to significant security risks, including unauthorized access and control over vulnerable systems.