Mehrere Schwachstellen (CVE-2026-9432, CVE-2026-9433, CVE-2026-9434, CVE-2026-9435, CVE-2026-9436, CVE-2026-9455, CVE-2026-9456) in Totolink
⚠️ CVE-Referenzen:
CVE-2026-9432
CVE-2026-9433
CVE-2026-9434
CVE-2026-9435
CVE-2026-9436
CVE-2026-9455
CVE-2026-9456
Totolink - A8000ru - CRITICAL - CVE-2026-9434.
A security vulnerability has been identified in the web management interface of the Totolink A8000RU router. Specifically, the issue is found in the 'setWiFiWpsCfg' function of the '/cgi-bin/cstecgi.cgi' file. By manipulating the 'wscDisabled' argument, an attacker can perform OS command injection, potentially allowing remote exploitation of the device. The exploit has been made public, raising concerns for users who may be at risk. It is crucial for affected users to patch their devices with the latest firmware updates to mitigate this vulnerability.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io