CVE-2026-1547: Totolink a7000r Firmware
Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.
A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected products
- Totolink a7000r Firmware: version 4.1cu.4154 only
Published 2026-01-28. Last modified 2026-06-17.