Vulnerability Description
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | Nr1800X Firmware | 9.1.0u.6279_b20210910 |
| Totolink | Nr1800X | - |
Related Weaknesses (CWE)
References
- https://lavender-bicycle-a5a.notion.site/TOTOLINK-NR1800X-setWanCfg-2e453a41781fExploitThird Party Advisory
- https://vuldb.com/?ctiid.342302Permissions RequiredVDB Entry
- https://vuldb.com/?id.342302Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.735787Third Party AdvisoryVDB Entry
- https://www.totolink.net/Product
FAQ
What is CVE-2026-1326?
CVE-2026-1326 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This...
How severe is CVE-2026-1326?
CVE-2026-1326 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1326?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink Nr1800X Firmware, Totolink Nr1800X.