CVE-2026-9477: Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9477?
CVE-2026-9477 has a severity rating of critical with a score of 9.8.
What types of systems are affected by CVE-2026-9477?
CVE-2026-9477 affects the Totolink A8000RU devices running version 7.1cu.643_b20200521.
How do I fix CVE-2026-9477?
To mitigate CVE-2026-9477, it is recommended to update the firmware of the Totolink A8000RU to the latest version.
What is the main exploit of CVE-2026-9477?
The main exploit of CVE-2026-9477 is an OS command injection vulnerability through the setAccessDeviceCfg function.
What can attackers achieve with CVE-2026-9477?
Attackers exploiting CVE-2026-9477 can execute arbitrary OS commands on the affected system.