CVE-2026-9432: Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection
A security flaw has been discovered in Totolink A8000RU 7.1cu.643b20200521. This vulnerability affects the function setWiFiAdvancedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument bgProtection results in os command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9432?
CVE-2026-9432 has a critical severity rating of 9.8.
What types of attacks are possible due to CVE-2026-9432?
CVE-2026-9432 allows for OS command injection attacks due to vulnerabilities in the setWiFiAdvancedCfg function.
How can CVE-2026-9432 be mitigated?
Mitigation for CVE-2026-9432 involves updating the Totolink A8000RU firmware to the latest version that addresses this vulnerability.
What specific component of the Totolink A8000RU is affected by CVE-2026-9432?
CVE-2026-9432 affects the Web Management Interface, specifically the function setWiFiAdvancedCfg in the cstecgi.cgi file.
What result can occur from exploiting CVE-2026-9432?
Exploiting CVE-2026-9432 could allow an attacker to execute arbitrary OS commands, compromising the device.