CVE-2026-9435: Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection
A vulnerability was detected in Totolink A8000RU 7.1cu.643b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Totolink A8000RU Web Management Interface (cstecgi.cgi setQosCfg)to a version that resolves this vulnerability.Fixed in 7.1cu.643_b20200521 - Compensating control
Restrict access to the Totolink Web Management Interface (including /cgi-bin/cstecgi.cgi and function setQosCfg) so it cannot be reached from the internet; allow only trusted IPs/networks (e.g., via firewall/ACL).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9435?
CVE-2026-9435 has a severity score of 9.8, categorized as critical.
What is the vulnerability CVE-2026-9435 related to?
CVE-2026-9435 is related to an OS command injection vulnerability in the setQosCfg function of the Totolink A8000RU web management interface.
How can CVE-2026-9435 be exploited?
CVE-2026-9435 can be exploited by manipulating the 'enable' argument in the /cgi-bin/cstecgi.cgi file, leading to potential remote command execution.
What versions of Totolink A8000RU are affected by CVE-2026-9435?
CVE-2026-9435 affects the Totolink A8000RU version 7.1cu.643_b20200521.
How do I fix CVE-2026-9435?
To fix CVE-2026-9435, it is recommended to update the firmware of the Totolink A8000RU to a version that addresses this vulnerability.