PT-2026-36975 · Totolink · A8000Ru

Ltzhust2

·

Published

2026-05-05

·

Updated

2026-05-05

·

CVE-2026-7823

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
A security flaw has been discovered in Totolink A8000RU 7.1cu.643 b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7823

Affected Products

A8000Ru