Mehrere Schwachstellen (CVE-2026-7240, CVE-2026-7241, CVE-2026-7242, CVE-2026-7243, CVE-2026-7244) in Totolink

Totolink - A8000ru - CRITICAL - CVE-2026-7240. A vulnerability exists within the Totolink A8000RU due to improper handling of user input in the setVpnAccountCfg function located in /cgi-bin/cstecgi.cgi. This weakness allows an attacker to execute arbitrary operating system commands via crafted requests. This command injection can be exploited remotely, posing significant risks to the device's security and integrity. Users are encouraged to review their configurations and update to mitigate the potential threat posed by this publicly disclosed exploit. BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io