CVE-2026-9454: Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection
A flaw has been found in Totolink A8000RU 7.1cu.643b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote web management access on the device; if remote management is required, restrict it to a small set of trusted management IPs or management VLAN only to prevent remote exploitation.
Totolink A8000RU Web Management Interface (/cgi-bin/cstecgi.cgi) remote_management = disabled - Configuration
Restrict access to the /cgi-bin/cstecgi.cgi endpoint (especially the setOpenVpnCertGenerationCfg function) so only authorized management hosts can reach it (ACLs on the device or upstream).
/cgi-bin/cstecgi.cgi (setOpenVpnCertGenerationCfg) access_control = trusted_ips_only - Compensating control
Deploy perimeter controls (firewall, WAF, or reverse proxy) to block or filter requests to /cgi-bin/cstecgi.cgi and to detect/mitigate command-injection patterns targeting setOpenVpnCertGenerationCfg; restrict access to the device management interface to trusted networks.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9454?
CVE-2026-9454 has a critical severity rating of 9.8.
What vulnerabilities does CVE-2026-9454 exploit?
CVE-2026-9454 exploits the OS command injection vulnerability found in the setOpenVpnCertGenerationCfg function.
How do I fix CVE-2026-9454?
To fix CVE-2026-9454, update the Totolink A8000RU device to the latest firmware version that addresses this vulnerability.
What versions of software are affected by CVE-2026-9454?
CVE-2026-9454 affects the Totolink A8000RU version 7.1cu.643_b20200521.
What can attackers achieve with CVE-2026-9454?
Attackers can exploit CVE-2026-9454 to execute arbitrary operating system commands on the affected device.