CVE-2026-7136 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 27, 2026
Totolink A8000RU - Command Injection
Published: April 27, 2026Updated: April 27, 2026Remote Exploitable
Overview
Totolink A8000RU 7.1cu.643_b20200521 contains a command injection caused by manipulation of the "wanIdx" argument in /cgi-bin/cstecgi.cgi's setDmzCfg function, letting remote attackers execute OS commands, exploit requires no special privileges.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Remote attackers can execute arbitrary OS commands, potentially leading to full system compromise.
Mitigation
Update to the latest version or apply vendor patches addressing this issue.
References
Related Resources
Details
- CVE ID
- CVE-2026-7136
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- rejected
CWE
- CWE-77
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H