Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-7202

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument wscDisabled leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Ver en NVD

Análisis

This is an OS command injection vulnerability in the firmware of a specific Totolink router model. As it affects niche consumer hardware rather than software development tools, servers, or widely used infrastructure, it does not warrant the attention of the developer community.

Severidad

Puntaje: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-77CWE-78

EPSS

Probabilidad de explotación (próx. 30 días): 0.0125 (1.3%)
Percentil: 79.5%
EPSS: 2026-05-06

Descripción técnica

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument wscDisabled leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Publicada: 28/4/2026, 1:16:01
Última modificación: 28/4/2026, 20:24:58

Referencias

InicioEventosBlogRecursosEquipo