Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-1601

Опубликовано: 29 янв. 2026
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument FileName can lead to command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:totolink:a7000r_firmware:4.1cu.4154:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a7000r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.02014
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.3
github
8 месяцев назад

A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument FileName can lead to command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 6.3
fstec
8 месяцев назад

Уязвимость функции setUploadUserData() микропрограммного обеспечения роутеров TOTOLINK A7000R, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 80%
0.02014
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-74