Mehrere Schwachstellen (CVE-2026-9432, CVE-2026-9433, CVE-2026-9434, CVE-2026-9435, CVE-2026-9436, CVE-2026-9455, CVE-2026-9456) in Totolink

Totolink - A8000ru - CRITICAL - CVE-2026-9434. A security vulnerability has been identified in the web management interface of the Totolink A8000RU router. Specifically, the issue is found in the 'setWiFiWpsCfg' function of the '/cgi-bin/cstecgi.cgi' file. By manipulating the 'wscDisabled' argument, an attacker can perform OS command injection, potentially allowing remote exploitation of the device. The exploit has been made public, raising concerns for users who may be at risk. It is crucial for affected users to patch their devices with the latest firmware updates to mitigate this vulnerability. BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io