TopVuln

High-risk vulnerability digests

CVE-2026-7548

  • HIGH

Details

CVSS v3
8.8
CVSS v4
7.4
CVSS v2
9.0
NVD published
2026-05-01 03:16:01
EPSS
1.5% probability · 81.5th percentile — 2026-05-12
Affected versions
Totolink NR1800X firmware 9.1.0u.6279_B20210910
Summary
This is a remote command injection vulnerability in the web management interface of the widely deployed Totolink NR1800X wireless router. The flaw exists in the processing of the setUssd argument in the cstecgi.cgi endpoint. Remote attackers can send a crafted request to execute arbitrary system commands on the affected device.
Remediation
Apply the latest official firmware update from Totolink for the NR1800X router immediately. Until a patch is available, disable remote management of the router and restrict access to the web management interface to only trusted local networks.
Exploit info
This exploit has been publicly disclosed, with references to this issue documented in trusted public vulnerability databases. You may check Exploit-DB or GitHub for potential exploit details.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.