A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
References
Configurations
No configuration.
History
29 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md - | |
| References | () https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md#poc - |
28 Jan 2026, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-28 22:15
Updated : 2026-01-29 17:16
NVD link : CVE-2026-1547
Mitre link : CVE-2026-1547
CVE.ORG link : CVE-2026-1547
JSON object : View
Products Affected
No product.
