Vulnerability Description
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Such manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | Nr1800X Firmware | 9.1.0u.6279_b20210910 |
| Totolink | Nr1800X | - |
Related Weaknesses (CWE)
References
- https://lavender-bicycle-a5a.notion.site/TOTOLINK-NR1800X-setTracerouteCfg-2e453ExploitThird Party Advisory
- https://vuldb.com/?ctiid.342303Permissions RequiredVDB Entry
- https://vuldb.com/?id.342303Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.735790Third Party AdvisoryVDB Entry
- https://www.totolink.net/Product
FAQ
What is CVE-2026-1327?
CVE-2026-1327 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Ha...
How severe is CVE-2026-1327?
CVE-2026-1327 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1327?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink Nr1800X Firmware, Totolink Nr1800X.