TopVuln

High-risk vulnerability digests

CVE-2026-7538

  • HIGH

Details

CVSS v3
9.8
CVSS v4
8.9
CVSS v2
10.0
NVD published
2026-05-01 02:16:04
EPSS
1.2% probability · 79.5th percentile — 2026-05-12
Affected versions
Totolink A8000RU firmware 7.1cu.643_b20200521
Summary
This flaw exists in the CGI handler component of the /cgi-bin/cstecgi.cgi file in affected Totolink A8000RU routers. Manipulation of the `proto` argument allows unauthenticated remote attackers to inject and execute arbitrary OS commands. A public exploit is available for this vulnerability.
Remediation
No official vendor patch is currently available for this issue. Organizations should restrict external access to affected routers and consider replacing vulnerable devices with supported alternatives if updates are not released.
Exploit info
This exploit has been publicly disclosed, with references to this issue documented in trusted public vulnerability databases. You may check Exploit-DB or GitHub for potential exploit details.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.