Description
A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-04-30: | Advisory disclosed |
| 2026-04-30: | VulDB entry created |
| 2026-04-30: | VulDB entry last update |
Credits
NEWYM (VulDB User)
References
vuldb.com/vuln/360358 (VDB-360358 | Totolink NR1800X cstecgi.cgi sub_41A68C command injection)
vuldb.com/vuln/360358/cti (VDB-360358 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/804417 (Submit #804417 | Totolink C834FR-1C NR1800X command injection)
github.com/...lob/main/totolink nr1800x command injection.md
www.totolink.net/