PT-2026-35520 · Totolink · A8000Ru

Ltzhuster2

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7152

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
A vulnerability was identified in Totolink A8000RU 7.1cu.643 b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument telnet enabled leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7152

Affected Products

A8000Ru