PT-2026-35524 · Totolink · A8000Ru

Ltzhuster2

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7154

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
A weakness has been identified in Totolink A8000RU 7.1cu.643 b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument tty server can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7154

Affected Products

A8000Ru