CVE-2026-9455: Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9455?
The severity of CVE-2026-9455 is rated as critical with a score of 9.8.
How do I fix CVE-2026-9455?
To fix CVE-2026-9455, update the Totolink A8000RU firmware to the latest version provided by the manufacturer.
What is the impact of CVE-2026-9455?
CVE-2026-9455 allows for OS command injection, potentially leading to unauthorized remote access and control of the affected device.
Which component is affected by CVE-2026-9455?
CVE-2026-9455 affects the UploadOpenVpnCert function within the Web Management Interface of the Totolink A8000RU.
Can CVE-2026-9455 be exploited remotely?
Yes, CVE-2026-9455 can be exploited remotely due to the nature of the vulnerability in the web management interface.