


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such mani…
Published:
5 April 2026 at 22:00:00
Alert date:
6 April 2026 at 20:01:55
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A vulnerability identified in Totolink A8000R router version 5.9c.681_B20180413 allows remote authentication bypass. The issue affects the setLanguageCfg function in /cgi-bin/cstecgi.cgi file through manipulation of the langType argument. This results in missing authentication controls that can be exploited remotely. Public exploits are available making this vulnerability particularly dangerous for affected devices.
Technical details
Mitigation steps:
Affected products:
Totolink A8000R
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5676
https://github.com/skeetabc/CVE-TOTOLINK-A800R/blob/main/vuln1_auth_bypass.md
https://vuldb.com/submit/792433
https://vuldb.com/vuln/355503
https://vuldb.com/vuln/355503/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
