CVE-2026-9408 | Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface /cgi-bin/cstecgi.cgi setStaticDhcpRules enable os command injection
A vulnerability, which was classified as critical, was found in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setStaticDhcpRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enable results in os command injection.
This vulnerability was named CVE-2026-9408. The attack may be performed from remote. In addition, an exploit is available.VulDB Recent EntriesRead More