peter bassill · operator
$ cve CVE-2026-7139 JSON

CVE-2026-7139

9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mode causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.25% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2026-04-27
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD