CVE-2026-9543: Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
A vulnerability has been found in Totolink N300RH 6.1c.1353B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the Web Management Interface or remote (WAN) management on the device until a vendor fix is available.
Totolink N300RH Web Management Interface (/cgi-bin/cstecgi.cgi) web_management_interface (remote access) = disabled - Configuration
Restrict access to the management interface to the local network (LAN) or to a small set of trusted IP addresses.
Totolink N300RH Web Management Interface management_access = LAN-only or restricted to trusted IPs - Compensating control
At the network edge or firewall, block or filter access to the device's web-management interface (HTTP/HTTPS endpoints such as /cgi-bin/cstecgi.cgi) from untrusted networks until a patch is installed.
- Operational
Monitor device and network logs for signs of exploitation of the web management interface, obtain and apply the vendor firmware/security update when it is released, and after updating rotate administrative credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9543?
The severity of CVE-2026-9543 is critical with a rating of 9.8.
How do I fix CVE-2026-9543?
To fix CVE-2026-9543, update the Totolink N300RH to the latest firmware version provided by the vendor.
What kind of attack is associated with CVE-2026-9543?
CVE-2026-9543 is associated with OS command injection attacks that can be executed remotely.
Which component is affected by CVE-2026-9543?
CVE-2026-9543 affects the Web Management Interface, specifically the function setPasswordCfg in the file /cgi-bin/cstecgi.cgi.
Is remote exploitation possible for CVE-2026-9543?
Yes, CVE-2026-9543 can be exploited remotely due to the nature of the vulnerability.