Mehrere Schwachstellen (CVE-2026-9384, CVE-2026-9385, CVE-2026-9386, CVE-2026-9387, CVE-2026-9388, CVE-2026-9404, CVE-2026-9405, CVE-2026-9406) in Totolink
⚠️ CVE-Referenzen:
CVE-2026-9384
CVE-2026-9385
CVE-2026-9386
CVE-2026-9387
CVE-2026-9388
CVE-2026-9404
CVE-2026-9405
CVE-2026-9406
Totolink - A8000ru - CRITICAL - CVE-2026-9387.
A security flaw has been identified in the Totolink A8000RU's web management interface, specifically within the function setUpgradeFW of the /cgi-bin/cstecgi.cgi file. By manipulating the resetFlags argument, an attacker can execute OS commands remotely, exposing the system to potential exploitation. The details of the exploit have been made public, raising concerns for users of the affected product.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io