Totolink A8000Ru vulnerabilities
50 known vulnerabilities affecting totolink/a8000ru.
Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL50
Vulnerabilities
Page 2 of 3
CVE-2026-9457P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-25
CVE-2026-9457 [CRITICAL] CWE-77 CVE-2026-9457: A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been publi
cvelistv5nvd
CVE-2026-9435P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-25
CVE-2026-9435 [CRITICAL] CWE-77 CVE-2026-9435: A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the fu
A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and
cvelistv5nvd
CVE-2026-9478P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-25
CVE-2026-9478 [CRITICAL] CWE-77 CVE-2026-9478: A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function set
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to
cvelistv5nvd
CVE-2026-9455P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-25
CVE-2026-9455 [CRITICAL] CWE-77 CVE-2026-9455: A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the funct
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to
cvelistv5nvd
CVE-2026-9475P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-25
CVE-2026-9475 [CRITICAL] CWE-77 CVE-2026-9475: A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function se
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and ma
cvelistv5nvd
CVE-2026-7538P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-01
CVE-2026-7538 [CRITICAL] CWE-77 CVE-2026-7538: A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the funct
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument proto leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-7154P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-27
CVE-2026-7154 [CRITICAL] CWE-77 CVE-2026-7154: A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function se
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument tty_server can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the publi
nvd
CVE-2026-7152P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-27
CVE-2026-7152 [CRITICAL] CWE-77 CVE-2026-7152: A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument telnet_enabled leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and migh
nvd
CVE-2026-7137P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-27
CVE-2026-7137 [CRITICAL] CWE-77 CVE-2026-7137: A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the
A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument sambaEnabled leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly a
nvd
CVE-2026-7155P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-27
CVE-2026-7155 [CRITICAL] CWE-77 CVE-2026-7155: A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the
A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may b
nvd
CVE-2026-9386P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-24
CVE-2026-9386 [CRITICAL] CWE-77 CVE-2026-9386: A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function set
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument lang leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.
cvelistv5nvd
CVE-2026-7242P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-28
CVE-2026-7242 [CRITICAL] CWE-77 CVE-2026-7242: A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function set
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enabled can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may
nvd
CVE-2026-9388P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-24
CVE-2026-9388 [CRITICAL] CWE-77 CVE-2026-9388: A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument mode can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made a
cvelistv5nvd
CVE-2026-9436P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-25
CVE-2026-9436 [CRITICAL] CWE-77 CVE-2026-9436: A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be
cvelistv5nvd
CVE-2026-7156P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-27
CVE-2026-7156 [CRITICAL] CWE-77 CVE-2026-7156: A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteS
A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument HTTP results in os command injection. The attack may be launched remotely. The exploit is now public and may be used.
nvd
CVE-2026-7125P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-27
CVE-2026-7125 [CRITICAL] CWE-77 CVE-2026-7125: A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is th
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-7139P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-27
CVE-2026-7139 [CRITICAL] CWE-77 CVE-2026-7139: A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWi
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mode causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
nvd
CVE-2026-7123P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-04-27
CVE-2026-7123 [CRITICAL] CWE-77 CVE-2026-7123: A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvC
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument setIptvCfg results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
nvd
CVE-2026-9406P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-25
CVE-2026-9406 [CRITICAL] CWE-77 CVE-2026-9406: A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function set
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the publ
cvelistv5nvd
CVE-2026-9433P2CRITICALCVSS 9.8v7.1cu.643_b202005212026-05-25
CVE-2026-9433 [CRITICAL] CWE-77 CVE-2026-9433: A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the funct
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been made available to the pub
cvelistv5nvd