CVE-2026-9404: Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection
A vulnerability was identified in Totolink A8000RU 7.1cu.643b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
/cgi-bin/cstecgi.cgifrom your environment.If possible, remove or disable execution of the vulnerable CGI endpoint (/cgi-bin/cstecgi.cgi) or disable CGI handling for this endpoint to prevent invocation of setDdnsCfg.
- Configuration
Disable DDNS / avoid using the setDdnsCfg function in the router Web Management Interface (remove any configured DDNS providers or turn off DDNS) to prevent triggering the vulnerable code path.
Web Management Interface (cstecgi.cgi) DDNS (setDdnsCfg) = disabled - Configuration
Disable remote/ WAN access to the Web Management Interface or restrict access to trusted management IP addresses only.
Web Management Interface Remote web management access = disabled or restricted to LAN/trusted IPs - Compensating control
Block or restrict access to /cgi-bin/cstecgi.cgi and the router management ports from untrusted networks at the perimeter firewall or by ACLs; ensure the management interface is not reachable from the Internet.
- Operational
Monitor device logs for signs of exploitation, isolate affected devices if compromise is suspected, and apply vendor-supplied updates or patches for Totolink A8000RU as soon as they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9404?
The severity of CVE-2026-9404 is critical with a score of 9.8.
How does CVE-2026-9404 affect Totolink A8000RU?
CVE-2026-9404 affects the Totolink A8000RU by allowing os command injection through the setDdnsCfg function in the web management interface.
What type of attack can exploit CVE-2026-9404?
CVE-2026-9404 can be exploited through a remote attack via os command injection.
How can I mitigate the risks associated with CVE-2026-9404?
To mitigate CVE-2026-9404, it is recommended to apply patches or updates provided by the vendor for the affected version.
Which component of the Totolink A8000RU is affected by CVE-2026-9404?
The affected component of the Totolink A8000RU is the Web Management Interface, specifically the cstecgi.cgi file.