Mehrere Schwachstellen (CVE-2026-7037, CVE-2026-7122) in Totolink
⚠️ CVE-Referenzen:
CVE-2026-7037
CVE-2026-7122
Totolink - A8000ru - CRITICAL - CVE-2026-7037.
A security flaw in the Totolink A8000RU router, specifically in the CGI Handler component, allows for remote command injection. This vulnerability is present in the function setVpnPassCfg of the cgi-bin/cstecgi.cgi file and is triggered by manipulating the pptpPassThru argument. An attacker can exploit this flaw from a remote location, potentially compromising the device's integrity. The exploit has been publicly released, highlighting the urgency for users to apply necessary patches and mitigate risks associated with unauthorized access.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io