9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.
AI Analysis
OS command injection vulnerability in Totolink A8000RU Web Management Interface
Basic Information
ID
CVE-2026-9454
Source
VulDB
Published
May 25, 2026 at 11:30
Affected Product
Vendor
Totolink
Product
A8000RU
Version
7.1cu.643_b20200521
Affected Versions
Totolink A8000RU 7.1cu.643_b20200521
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Totolink
Product
A8000RU
Version
7.1cu.643_b20200521