


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a mani…
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 04:01:07
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A remote command injection vulnerability (CVE-2026-7548) was discovered in Totolink NR1800X router firmware version 9.1.0u.6279_B20210910. The vulnerability affects the sub_41A68C function in /cgi-bin/cstecgi.cgi file. Attackers can exploit this by manipulating the setUssd argument to achieve command injection. The vulnerability can be exploited remotely and public exploits are now available. This presents a high risk to affected devices as it allows remote code execution on network infrastructure equipment.
Technical details
Mitigation steps:
Affected products:
Totolink NR1800X
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7548
https://github.com/newym/cve/blob/main/totolink%20nr1800x%20command%20injection.md
https://vuldb.com/submit/804417
https://vuldb.com/vuln/360358
https://vuldb.com/vuln/360358/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
