Description
A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-04-06: | Advisory disclosed |
| 2026-04-06: | VulDB entry created |
| 2026-04-06: | VulDB entry last update |
Credits
skeet (VulDB User)
References
vuldb.com/vuln/355503 (VDB-355503 | Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication)
vuldb.com/vuln/355503/cti (VDB-355503 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/792433 (Submit #792433 | Totolink A8000R V5.9c.681_B20180413 Improper Authentication)
github.com/...-TOTOLINK-A800R/blob/main/vuln1_auth_bypass.md
www.totolink.net/