CVE-2026-1623

MEDIUM

Totolink A7000r Firmware - Command Injection

Title source: rule

Description

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Scores

CVSS v3 6.3
EPSS 0.0206
EPSS Percentile 83.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-77 CWE-74
Status published

Affected Products (1)

totolink/a7000r_firmware

Timeline

Published Jan 29, 2026
Tracked Since Feb 18, 2026