CVE-2026-9543: Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9543?
The severity of CVE-2026-9543 is critical with a rating of 9.8.
How do I fix CVE-2026-9543?
To fix CVE-2026-9543, update the Totolink N300RH to the latest firmware version provided by the vendor.
What kind of attack is associated with CVE-2026-9543?
CVE-2026-9543 is associated with OS command injection attacks that can be executed remotely.
Which component is affected by CVE-2026-9543?
CVE-2026-9543 affects the Web Management Interface, specifically the function setPasswordCfg in the file /cgi-bin/cstecgi.cgi.
Is remote exploitation possible for CVE-2026-9543?
Yes, CVE-2026-9543 can be exploited remotely due to the nature of the vulnerability.