CVE-2026-9455: Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection

Published May 25, 2026
·
Updated

A vulnerability has been found in Totolink A8000RU 7.1cu.643b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

Affected Software

1 affected component
TOTOLINK A8000RU=7.1cu.643_b20200521

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Totolink A8000RU /cgi-bin/cstecgi.cgi from your environment.

    Remove or disable the /cgi-bin/cstecgi.cgi script (or the vulnerable UploadOpenVpnCert handler) on impacted devices to eliminate the vulnerable code path if disabling the feature is not possible.

  2. Configuration

    Disable remote/remote-WAN web management (turn off remote management) so the web management interface is not reachable from untrusted networks.

    Totolink A8000RU Web Management Interface remote_web_management = disabled
  3. Configuration

    Disable the UploadOpenVpnCert/OpenVPN certificate upload functionality or any feature that accepts user-supplied FileName via the web UI to prevent use of the vulnerable endpoint.

    Totolink A8000RU Web Management Interface UploadOpenVpnCert (OpenVPN certificate upload) = disabled
  4. Compensating control

    Restrict access to the device management interface to trusted IPs only (e.g., management VLAN, VPN or firewall rules) and block access from the Internet/WAN to prevent remote exploitation.

  5. Operational

    Assume possible compromise: rotate administrative credentials and device keys/certificates, review device logs for signs of exploitation, and isolate or rebuild devices showing suspicious activity.

Event History

May 25, 2026
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Apr 28, 58520
Event
via FIRST·05:55 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9455?

The severity of CVE-2026-9455 is rated as critical with a score of 9.8.

2

How do I fix CVE-2026-9455?

To fix CVE-2026-9455, update the Totolink A8000RU firmware to the latest version provided by the manufacturer.

3

What is the impact of CVE-2026-9455?

CVE-2026-9455 allows for OS command injection, potentially leading to unauthorized remote access and control of the affected device.

4

Which component is affected by CVE-2026-9455?

CVE-2026-9455 affects the UploadOpenVpnCert function within the Web Management Interface of the Totolink A8000RU.

5

Can CVE-2026-9455 be exploited remotely?

Yes, CVE-2026-9455 can be exploited remotely due to the nature of the vulnerability in the web management interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203