Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-7241

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

Ver en NVD

Análisis

This is a remote command injection vulnerability in a specific consumer-grade router model. While the CVSS score is high and an exploit is public, the product is niche hardware and not part of the common software development or Linux server stack used by the community.

Severidad

Puntaje: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-77CWE-78

EPSS

Probabilidad de explotación (próx. 30 días): 0.0125 (1.3%)
Percentil: 79.5%
EPSS: 2026-05-06

Descripción técnica

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

Publicada: 28/4/2026, 9:16:17
Última modificación: 28/4/2026, 20:24:20

Referencias

InicioEventosBlogRecursosEquipo