Vulnerability Database

322,129

Total vulnerabilities in the database

CVE-2026-1548

A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument url causes command injection. The attack can be initiated remotely. The exploit has been published and may be used.

  • Published: Jan 28, 2026
  • Updated: Feb 10, 2026
  • CVE: CVE-2026-1548
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.3
  • AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS v2:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:L/Au:S/C:P/I:P/A:P