← Terug naar overzicht

A command injection vulnerability was identified in TOTOLINK NR1800X router firmware version 9.1.0u.6681_B20230703. The vulnerability exists in the setUssd function within the /cgi-bin/cstecgi.cgi file. An attacker can manipulate the 'ussd' argument to inject arbitrary commands. The attack can be launched remotely without requiring physical access to the device. A public exploit is already available, increasing the risk of active exploitation. This type of vulnerability in network routers poses significant risk to network security and integrity. The affected product is a 5G NR router commonly used for broadband connectivity.

Affected products

  • TOTOLINK NR1800X 9.1.0u.6681_B20230703

Related CVE's

  • CVE-2026-82597

Categories

  • Mobile & IoT
  • Network Infrastructure