CVE-2026-1547
A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi
A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection.
It is possible to launch the attack remotely. The exploit is now public and may be used.
MEDIUM · CVSS 6.3
EPSS 0.0067
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0