CVE-2026-9406: Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection
A weakness has been identified in Totolink A8000RU 7.1cu.643b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9406?
The severity of CVE-2026-9406 is critical with a score of 9.8.
How do I fix CVE-2026-9406?
To fix CVE-2026-9406, update the Totolink A8000RU firmware to a version that addresses the command injection vulnerability.
What platforms are affected by CVE-2026-9406?
CVE-2026-9406 affects the Totolink A8000RU router running firmware version 7.1cu.643_b20200521.
What type of vulnerability is CVE-2026-9406?
CVE-2026-9406 is classified as an OS command injection vulnerability.
What can an attacker achieve with CVE-2026-9406?
An attacker can execute remote OS command injections via the setRemoteCfg function in the web management interface.