PatchSiren

Totolink CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Totolink CVE published 2026-05-25

CVE-2026-9475

A command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability is located in the setIpQosRules function within the /cgi-bin/cstecgi.cgi endpoint of the web management interface. The Comment parameter is improperly sanitized, allowing an attacker to inject and execute arbitrary operating system commands. This vulnerability can be exp [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9458

A remote OS command injection vulnerability exists in Totolink A8000RU firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setWanCfg` function within the `/cgi-bin/cstecgi.cgi` endpoint of the web management interface. The `enabled` parameter is susceptible to command injection, allowing unauthenticated remote attackers to execute arbitrary operating system commands. The CVSS 4.0 score [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9457

A command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability is located in the UploadFirmwareFile function within the /cgi-bin/cstecgi.cgi endpoint of the web management interface. The FileName parameter is not properly sanitized, allowing remote attackers to inject and execute arbitrary operating system commands without authentication. Th [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9456

A command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability is located in the `setOpenVpnCfg` function within the `/cgi-bin/cstecgi.cgi` web management interface endpoint. The `enabled` parameter is not properly sanitized, allowing remote attackers to inject and execute arbitrary operating system commands without authentication. [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9455

A command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability is located in the UploadOpenVpnCert function within the /cgi-bin/cstecgi.cgi endpoint of the web management interface. The FileName parameter is not properly sanitized, allowing an attacker to inject arbitrary operating system commands. This vulnerability can be exploited remotel [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9436

A command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setL2tpServerCfg` function within the `/cgi-bin/cstecgi.cgi` web management interface endpoint. The `enable` parameter is not properly sanitized, allowing remote attackers to inject and execute arbitrary operating system commands without authentication. This vulne [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9435

A command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setQosCfg` function within the `/cgi-bin/cstecgi.cgi` endpoint of the web management interface. The `enable` parameter is not properly sanitized, allowing remote attackers to inject and execute arbitrary operating system commands without authentication. T [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9434

A command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setWiFiWpsCfg` function within the `/cgi-bin/cstecgi.cgi` web management interface endpoint. The `wscDisabled` parameter is not properly sanitized before being passed to system shell execution, allowing remote attackers to inject arbitrary operating syste [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9433

A command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setMacFilterRules` function within the `/cgi-bin/cstecgi.cgi` endpoint of the web management interface. The `enable` parameter is not properly sanitized, allowing remote attackers to inject and execute arbitrary operating system commands without authentic [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9408

A command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability is located in the `setStaticDhcpRules` function within the `/cgi-bin/cstecgi.cgi` endpoint of the web management interface. The `enable` parameter is not properly sanitized, allowing remote attackers to inject and execute arbitrary operating system commands without authe [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9406

A command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setRemoteCfg` function within the `/cgi-bin/cstecgi.cgi` web management interface endpoint. The `enable` parameter is susceptible to OS command injection, allowing remote unauthenticated attackers to execute arbitrary commands on the underlying operating system. T [truncated]

HIGH Totolink CVE published 2026-05-24

CVE-2026-9404

A command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability is located in the `setDdnsCfg` function within the `/cgi-bin/cstecgi.cgi` endpoint of the web management interface. The `provider` parameter is not properly sanitized, allowing an unauthenticated remote attacker to inject and execute arbitrary operating system commands. The CVSS [truncated]

HIGH Totolink CVE published 2026-05-24

CVE-2026-9387

A command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The vulnerability is located in the setUpgradeFW function within the /cgi-bin/cstecgi.cgi endpoint of the web management interface. The resetFlags parameter is susceptible to OS command injection, allowing remote attackers to execute arbitrary commands without authentication. The vulnerability has [truncated]

HIGH Totolink CVE published 2026-05-24

CVE-2026-9386

A remote OS command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setLanguageCfg` function within the `/cgi-bin/cstecgi.cgi` web management interface endpoint. The `lang` parameter is not properly sanitized, allowing an unauthenticated remote attacker to inject arbitrary operating system commands. The CVSS 4.0 [truncated]

HIGH Totolink CVE published 2026-05-24

CVE-2026-9384

A command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setDiagnosisCfg` function within the `/cgi-bin/cstecgi.cgi` endpoint of the web management interface. The `ip` parameter is not properly sanitized, allowing an unauthenticated remote attacker to inject arbitrary operating system commands. Successful explo [truncated]

HIGH Totolink CVE published 2026-04-28

CVE-2026-7219

A buffer overflow vulnerability was found in Totolink N300RT 3.4.0-B20250430. The vulnerability affects an unknown function of the file /boafrm/formIpQoS. A manipulation of the argument entry_name can lead to buffer overflow. The attack may be performed from remote. This vulnerability has been publicly disclosed and may be used by attackers. Network administrators and security teams should be aware of thi [truncated]

HIGH Totolink CVE published 2026-04-28

CVE-2026-7218

CVE-2026-7218 is a buffer overflow vulnerability in Totolink N300RT 3.4.0-B20250430, impacting the function is_cmd_string_valid of the file /boafrm/formWsc in the component libapmib.so. The vulnerability allows for remote exploitation through manipulation of the localPin argument. Network administrators and security teams should be aware of this vulnerability and take immediate action to mitigate the risk [truncated]

HIGH Totolink CVE published 2026-04-28

CVE-2026-7204

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Users should assess the vulnerability and apply patches [truncated]

HIGH Totolink CVE published 2026-04-28

CVE-2026-7203

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521, affecting the setUrlFilterRules function in the /cgi-bin/cstecgi.cgi file of the CGI Handler component. The manipulation of the 'enable' argument results in OS command injection, allowing for remote exploitation. This issue has a high impact due to its remote exploitability and potential for command injection.

HIGH Totolink CVE published 2026-04-28

CVE-2026-7202

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521, affecting the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi in the CGI Handler component. The manipulation of the argument wscDisabled leads to OS command injection, which can be initiated remotely. This vulnerability has been publicly disclosed and may be used by attackers. Users of affected products should apply patches [truncated]

MEDIUM Totolink CVE published 2026-04-07

CVE-2026-5692

CVE-2026-5692 is an os command injection vulnerability impacting Totolink A7100RU 7.4cu.2313_b20191024. The vulnerability affects the setGameSpeedCfg function in /cgi-bin/cstecgi.cgi, allowing remote attackers to inject os commands by manipulating the enable argument. The attack may be performed from remote. The exploit has been made public and could be used. Users and administrators should review the vul [truncated]

MEDIUM Totolink CVE published 2026-04-06

CVE-2026-5690

CVE-2026-5690 is a medium-severity vulnerability in Totolink A7100RU 7.4cu.2313_b20191024. The setRemoteCfg function in /cgi-bin/cstecgi.cgi is susceptible to os command injection via the enable argument. This issue can be exploited remotely. The CVE record was published on 2026-04-06T23:16:31.563Z and was last modified on 2026-07-24T09:10:00.153Z. Users should review the official CVE record and NVD entry [truncated]

MEDIUM Totolink CVE published 2026-04-06

CVE-2026-5688

CVE-2026-5688 is an os command injection vulnerability in Totolink A7100RU 7.4cu.2313_b20191024 in the setDdnsCfg function of /cgi-bin/cstecgi.cgi. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Users of affected products should prioritize patching or applying mitigations to prevent exploitation. This vulnerability has a CVSS score of 5.5 and is classified as [truncated]

LOW Totolink CVE published 2026-04-06

CVE-2026-5679

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. This vulnerability has a CVSS score of 2 and a severity of LOW. Users of affected products should assess their exposure and apply vendor remediation if available.

MEDIUM Totolink CVE published 2026-04-06

CVE-2026-5678

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. Users should assess the vulnerability and apply pat [truncated]

MEDIUM Totolink CVE published 2026-04-06

CVE-2026-5677

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The impacted component is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection. The attack may be initiated remotely. This issue allows for remote exploitation, potentially leading to unauthorized command execution.

HIGH TOTOLINK CVE published 2026-02-17

CVE-2026-26731

TOTOLINK A3002RU V2.1.1-B20211108.1455 contains a stack-based buffer overflow via the `routernamer` parameter in the `formDnsv6` function. Defenders should assess exposure, prioritize verification, and consider remediation. The vulnerability has a CVSS score of 8.8, indicating high severity. Network administrators and security teams must verify exposure, assess potential impact, and apply patches or mitig [truncated]