A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Title | Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection | |
| First Time appeared |
Totolink
Totolink a8000ru Firmware |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:o:totolink:a8000ru_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink
Totolink a8000ru Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-25T16:45:11.115Z
Reserved: 2026-05-24T09:15:21.440Z
Link: CVE-2026-9475
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T18:30:06Z