CVE-2026-9457: Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9457?
CVE-2026-9457 has a critical severity rating of 9.8.
How does CVE-2026-9457 affect the Totolink A8000RU?
CVE-2026-9457 allows for OS command injection through the UploadFirmwareFile function in the web management interface.
What are the potential impacts of exploiting CVE-2026-9457?
Exploitation of CVE-2026-9457 can lead to unauthorized command execution on the affected device.
How can I mitigate CVE-2026-9457?
To mitigate CVE-2026-9457, it is recommended to apply patches or updates provided by the manufacturer.
Is there a known fix for CVE-2026-9457?
As of now, there are no specific details on a permanent fix available for CVE-2026-9457.