CVE-2026-7823
Last modified
CVE-2026-7823 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7823?
How severe is CVE-2026-7823?
How do I fix CVE-2026-7823?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-78222A vulnerability exists in NGINX JavaScript where a malformed…7.5
- CVE-2026-78223Improper Verification of Cryptographic Signature vulnerabili…6.9
- CVE-2026-78224The XSLT Transformer Step builds a bare TransformerFactory w…8.2
- CVE-2026-78225A hardcoded cryptographic server key vulnerability exists in…9
- CVE-2026-78227NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a …6.5
- CVE-2026-78228Uncontrolled Recursion vulnerability in ash-project ash_oban…5.9
- CVE-2026-78230AshAi exposes Ash read actions to language-model tool calls.…6
- CVE-2026-78234A flaw was found in hawtio-operator. The operator reads the …9.9
- CVE-2026-78236An insecure PIN derivation mechanism in ABR allows a low-pri…8.8
- CVE-2026-78237Insufficient input validation in ABR allows a low-privileged…7.8
- CVE-2026-78238SOY Gallery contains a cross-site scripting vulnerability. …4.8
- CVE-2026-78239Xiiaozet LK100W exposes a critical management function that …9.8
Are you affected by CVE-2026-7823?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
