CVE-2022-41518
published 2022-10-06CVE-2022-41518: TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.84%
77.6th percentile
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | nr1800x_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TOTOLINK NR1800X 9.1.0u.6279_B20210910 /cgi-bin/cstecgi.cgi UploadFirmwareFile command injection (EUVD-2022-44711)
vuldb·2026-08-06·CVSS 9.8
CVE-2022-41518 [CRITICAL] TOTOLINK NR1800X 9.1.0u.6279_B20210910 /cgi-bin/cstecgi.cgi UploadFirmwareFile command injection (EUVD-2022-44711)
A vulnerability labeled as critical has been found in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected is the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. Executing a manipulation can lead to command injection.
This vulnerability is registered as CVE-2022-41518. The attack requires access to the local network. No exploit is available.
GHSA
GHSA-v4f2-wgpx-3p85: TOTOLINK NR1800X V9
ghsa_unreviewed·2022-10-06
CVE-2022-41518 [CRITICAL] CWE-77 GHSA-v4f2-wgpx-3p85: TOTOLINK NR1800X V9
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
No detection rules found.
No public exploits indexed.
2022-10-06
Published