CVE-2026-9456: Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enabled results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9456?
CVE-2026-9456 has a critical severity rating of 9.8.
What impact does CVE-2026-9456 have on affected systems?
CVE-2026-9456 allows remote attackers to perform OS command injection through the Web Management interface.
How do I fix CVE-2026-9456?
To mitigate CVE-2026-9456, users should update the Totolink A8000RU firmware to the latest version provided by the vendor.
Can CVE-2026-9456 be exploited remotely?
Yes, CVE-2026-9456 can be exploited remotely without authentication.
Which components are affected by CVE-2026-9456?
CVE-2026-9456 affects the setOpenVpnCfg function in the /cgi-bin/cstecgi.cgi of the Totolink A8000RU's Web Management Interface.