216.73.217.22

CVE-2026-9454

· Published 25/05/2026 13:16 · Modified 26/05/2026 18:59

Labels: CVE-2026-9454 2026-05-25CVE-2026-9454CWE-77[email protected]

Essential information

Published
25/05/2026 13:16
Modified
26/05/2026 18:59
Author
Creator
CVSS
8.9 HIGH (v3) 8.9 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
totolink / a8000ru cpe:2.3:a:totolink:a8000ru:7.1cu.643_b20200521:*:*:*:*:*:*:*

References