CVE-2026-9455: Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection
A vulnerability has been found in Totolink A8000RU 7.1cu.643b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Totolink A8000RU /cgi-bin/cstecgi.cgifrom your environment.Remove or disable the /cgi-bin/cstecgi.cgi script (or the vulnerable UploadOpenVpnCert handler) on impacted devices to eliminate the vulnerable code path if disabling the feature is not possible.
- Configuration
Disable remote/remote-WAN web management (turn off remote management) so the web management interface is not reachable from untrusted networks.
Totolink A8000RU Web Management Interface remote_web_management = disabled - Configuration
Disable the UploadOpenVpnCert/OpenVPN certificate upload functionality or any feature that accepts user-supplied FileName via the web UI to prevent use of the vulnerable endpoint.
Totolink A8000RU Web Management Interface UploadOpenVpnCert (OpenVPN certificate upload) = disabled - Compensating control
Restrict access to the device management interface to trusted IPs only (e.g., management VLAN, VPN or firewall rules) and block access from the Internet/WAN to prevent remote exploitation.
- Operational
Assume possible compromise: rotate administrative credentials and device keys/certificates, review device logs for signs of exploitation, and isolate or rebuild devices showing suspicious activity.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9455?
The severity of CVE-2026-9455 is rated as critical with a score of 9.8.
How do I fix CVE-2026-9455?
To fix CVE-2026-9455, update the Totolink A8000RU firmware to the latest version provided by the manufacturer.
What is the impact of CVE-2026-9455?
CVE-2026-9455 allows for OS command injection, potentially leading to unauthorized remote access and control of the affected device.
Which component is affected by CVE-2026-9455?
CVE-2026-9455 affects the UploadOpenVpnCert function within the Web Management Interface of the Totolink A8000RU.
Can CVE-2026-9455 be exploited remotely?
Yes, CVE-2026-9455 can be exploited remotely due to the nature of the vulnerability in the web management interface.