CVE-2026-5676

HIGH

Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication

Title source: cna

Description

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used.

Scores

CVSS v3 7.3
EPSS 0.0009
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-306
Status published
Products (1)
Totolink/A8000R 5.9c.681_B20180413
Published Apr 06, 2026
Tracked Since Apr 07, 2026