CVE-2026-1623

Confirmed PUBLISHED

Totolink A7000R cstecgi.cgi setUpgradeFW command injection

Vendor: TOTOLINK Product: A7000R

Not yet in CISA KEV

Exploited in the wild Active exploitation observed PoC available

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
1
Unique Attacker IPs
1
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
5.3 Medium EPSS 2.2%

At a Glance

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

edge
CVE Published
Jan 29, 2026
Exploitation Reported
Jul 30, 2026
CVSS
5.3 Medium
EPSS
2.2%
Remote Low complexity No user interaction

Sensor telemetry available

Affected Versions

Vendor Product Version Status
Totolink
A7000R

4.1cu.4154

Affected

CVE References

Show 1 more reference