CVE-2026-7243

CRITICAL

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulat...

Affects 0 products across 2 vendors.

BCS7.47
CVSS 3.19.8
CVSS v48.9
EPSS2.4%
Percentile83th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-77: Command Injection

Attacker injects operating system commands through application inputs passed to a shell or system call.

CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-77 CWE-78
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-77
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-77 CWE-78
Show all 11
via CWE-77
via CWE-77
via CWE-78
via CWE-77
via CWE-77
via CWE-77

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Totolink A8000RU 7.1cu.643_b20200521 allows for OS command injection via the setRadvdCfg function in the CGI Handler component, potentially leading to remote code execution.

BSID: BS-2026-GLOBAL-318048-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-7243?
A critical vulnerability in Totolink A8000RU 7.1cu.643_b20200521 allows for OS command injection via the setRadvdCfg function in the CGI Handler component, potentially leading to remote code execution.
What is the CVSS score for CVE-2026-7243?
CVE-2026-7243 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 2.4%.
Is CVE-2026-7243 actively exploited?
No confirmed active exploitation of CVE-2026-7243 as of 2026-05-30.
How do I remediate CVE-2026-7243?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-7243?
CVE-2026-7243 affects: Element, Totolink.
Vulnerability Details
CVE IDCVE-2026-7243
BSIDBS-2026-GLOBAL-318048-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-04-28
Last Modified2026-04-28
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument maxRtrAdvInterval leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is triggered by manipulating the maxRtrAdvInterval argument in the setRadvdCfg function within the /cgi-bin/cstecgi.cgi file. An attacker can exploit this to inject and execute arbitrary OS commands remotely.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Element —
Totolink —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 103 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashc9bea810ec5da53288a58399f3eee26299d66bab6dc406c4501dbd48090ce3828a55ffcb29354e9ca344b0a299ce91ac7fea6137d9255f87cb32a49fa4edd971
Related CVEs affecting Element
CVE-2024-32962 10.0 xml-crypto is an xml digital signature and encryption library for Node.js. In... CVE-2024-56829 10.0 Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary... CVE-2026-7546 9.8 A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B2... CVE-2026-6279 9.8 The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unau... CVE-2026-7719 9.8 A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. T...
View all Element CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →