A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. It has been rated as critical. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge leads to os command injection.
This vulnerability is listed as CVE-2026-7125. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. It has been declared as critical. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument addrPrefixLen can lead to os command injection.
This vulnerability is tracked as CVE-2026-7124. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. It has been classified as critical. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument setIptvCfg results in os command injection.
This vulnerability is identified as CVE-2026-7123. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521 and classified as critical. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection.
This vulnerability is referenced as CVE-2026-7122. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521 and classified as critical. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument wizard causes os command injection.
The identification of this vulnerability is CVE-2026-7121. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.