CVE-2023-51026: Totolink EX1800T Firmware

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.

Affected products

  • Totolink EX1800T Firmware: version 9.1.0cu.2112_b20220316 only

Published 2023-12-22. Last modified 2026-06-17.