CVE-2026-7548

HIGH

Totolink NR1800X cstecgi.cgi sub_41A68C command injection

Title source: cna
STIX 2.1

Description

A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Scores

CVSS v3 8.8
EPSS 0.0116
EPSS Percentile 78.7%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-74 CWE-77
Status published
Products (1)
Totolink/NR1800X 9.1.0u.6279_B20210910
Published May 01, 2026
Tracked Since May 01, 2026