CVE-2026-9404: Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection

Published May 24, 2026
·
Updated

A vulnerability was identified in Totolink A8000RU 7.1cu.643b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used.

Affected Software

1 affected component
TOTOLINK A8000RU=7.1cu.643_b20200521

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove /cgi-bin/cstecgi.cgi from your environment.

    If possible, remove or disable execution of the vulnerable CGI endpoint (/cgi-bin/cstecgi.cgi) or disable CGI handling for this endpoint to prevent invocation of setDdnsCfg.

  2. Configuration

    Disable DDNS / avoid using the setDdnsCfg function in the router Web Management Interface (remove any configured DDNS providers or turn off DDNS) to prevent triggering the vulnerable code path.

    Web Management Interface (cstecgi.cgi) DDNS (setDdnsCfg) = disabled
  3. Configuration

    Disable remote/ WAN access to the Web Management Interface or restrict access to trusted management IP addresses only.

    Web Management Interface Remote web management access = disabled or restricted to LAN/trusted IPs
  4. Compensating control

    Block or restrict access to /cgi-bin/cstecgi.cgi and the router management ports from untrusted networks at the perimeter firewall or by ACLs; ensure the management interface is not reachable from the Internet.

  5. Operational

    Monitor device logs for signs of exploitation, isolate affected devices if compromise is suspected, and apply vendor-supplied updates or patches for Totolink A8000RU as soon as they become available.

Event History

May 24, 2026
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Apr 28, 58520
Event
via FIRST·05:54 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9404?

The severity of CVE-2026-9404 is critical with a score of 9.8.

2

How does CVE-2026-9404 affect Totolink A8000RU?

CVE-2026-9404 affects the Totolink A8000RU by allowing os command injection through the setDdnsCfg function in the web management interface.

3

What type of attack can exploit CVE-2026-9404?

CVE-2026-9404 can be exploited through a remote attack via os command injection.

4

How can I mitigate the risks associated with CVE-2026-9404?

To mitigate CVE-2026-9404, it is recommended to apply patches or updates provided by the vendor for the affected version.

5

Which component of the Totolink A8000RU is affected by CVE-2026-9404?

The affected component of the Totolink A8000RU is the Web Management Interface, specifically the cstecgi.cgi file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203