PT-2026-30700 · Totolink · A8000R

Skeet

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-5676

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was identified in Totolink A8000R 5.9c.681 B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used.

Exploit

Fix

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-5676

Affected Products

A8000R