{"cve":"CVE-2026-1547","enrichment":{"created":"2026-01-29T09:08:57.414454+00:00","updated":"2026-06-18T05:30:15.893051+00:00","vendors":["totolink","totolink$PRODUCT$a7000r"]},"epss":{"score":0.0288},"mitre":{"cpes":["cpe:2.3:o:totolink:a7000r_firmware:*:*:*:*:*:*:*:*"],"created":"2026-01-28T22:02:10.788000+00:00","description":"A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.","metrics":{"cvssV2_0":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"},"cvssV3_0":{"score":6.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"cvssV4_0":{"score":5.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}},"mitre_repo_path":"cves/2026/1xxx/CVE-2026-1547.json","references":["https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md","https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md#poc","https://vuldb.com/?ctiid.343231","https://vuldb.com/?id.343231","https://vuldb.com/?submit.739713","https://www.totolink.net/"],"title":"Totolink A7000R cstecgi.cgi setUnloadUserData command injection","updated":"2026-02-23T09:02:20.499000+00:00","vendors":["totolink","totolink$PRODUCT$a7000r_firmware"],"weaknesses":["CWE-74","CWE-77"]},"nvd":{"cpes":["cpe:2.3:h:totolink:a7000r:-:*:*:*:*:*:*:*","cpe:2.3:o:totolink:a7000r_firmware:4.1cu.4154:*:*:*:*:*:*:*"],"created":"2026-01-28T22:15:55.853000+00:00","description":"A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.","metrics":{"cvssV2_0":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{"score":2.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-1547.json","references":["https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md","https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md#poc","https://vuldb.com/?ctiid.343231","https://vuldb.com/?id.343231","https://vuldb.com/?submit.739713","https://www.totolink.net/"],"title":null,"updated":"2026-06-17T10:16:02.790000+00:00","vendors":["totolink","totolink$PRODUCT$a7000r","totolink$PRODUCT$a7000r_firmware"],"weaknesses":["CWE-74","CWE-77"]},"opencve":{"changes":[{"created":"2026-01-28T22:15:00+00:00","data":[{"details":{"new":"A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.","old":null},"type":"description"},{"details":{"new":"Totolink A7000R cstecgi.cgi setUnloadUserData command injection","old":null},"type":"title"},{"details":{"added":["CWE-74","CWE-77"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md","https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md#poc","https://vuldb.com/?ctiid.343231","https://vuldb.com/?id.343231","https://vuldb.com/?submit.739713","https://www.totolink.net/"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV2_0":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"},"cvssV3_0":{"score":6.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"cvssV4_0":{"score":5.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"c1850e21-6dc0-4f04-be39-d4bcda1c1f21"},{"created":"2026-01-29T10:15:00+00:00","data":[{"details":["totolink","totolink$PRODUCT$a7000r"],"type":"first_time"},{"details":{"added":["totolink","totolink$PRODUCT$a7000r"],"removed":[]},"type":"vendors"}],"id":"cb42dbc1-27f2-4537-b3e4-ca5244f150df"},{"created":"2026-01-29T17:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"be1a7542-c45f-49be-8902-6bd55d4ab737"},{"created":"2026-02-09T17:00:00+00:00","data":[{"details":["totolink$PRODUCT$a7000r_firmware"],"type":"first_time"},{"details":{"added":["cpe:2.3:h:totolink:a7000r:-:*:*:*:*:*:*:*","cpe:2.3:o:totolink:a7000r_firmware:4.1cu.4154:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["totolink$PRODUCT$a7000r_firmware"],"removed":[]},"type":"vendors"}],"id":"a5d3b076-7485-4f24-9157-71071487a947"},{"created":"2026-02-23T09:15:00+00:00","data":[{"details":{"added":["cpe:2.3:o:totolink:a7000r_firmware:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"}],"id":"fcd8e660-dd6a-4287-b14d-33582e7961f2"}],"cpes":{"data":["cpe:2.3:h:totolink:a7000r:-:*:*:*:*:*:*:*","cpe:2.3:o:totolink:a7000r_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:totolink:a7000r_firmware:4.1cu.4154:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-01-28T22:02:10.788000+00:00","provider":"mitre"},"description":{"data":"A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"},"provider":"mitre"},"cvssV3_0":{"data":{"score":6.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"provider":"mitre"},"cvssV3_1":{"data":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"provider":"mitre"},"cvssV4_0":{"data":{"score":5.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"},"provider":"mitre"},"epss":{"data":{"score":0.0288},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md","https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md#poc","https://vuldb.com/?ctiid.343231","https://vuldb.com/?id.343231","https://vuldb.com/?submit.739713","https://www.totolink.net/"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":"Totolink A7000R cstecgi.cgi setUnloadUserData command injection","provider":"mitre"},"updated":{"data":"2026-04-18T14:45:03.136040+00:00","provider":"enrichment"},"vendors":{"data":["totolink","totolink$PRODUCT$a7000r","totolink$PRODUCT$a7000r_firmware"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-74","CWE-77"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-01-28T22:02:10.788000+00:00","description":"A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":["https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md","https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/01_RCE_setUnloadUserData_RCE.md#poc"],"title":"Totolink A7000R cstecgi.cgi setUnloadUserData command injection","updated":"2026-01-29T16:01:10.770000+00:00","vendors":[],"vulnrichment_repo_path":"2026/1xxx/CVE-2026-1547.json","weaknesses":[]}}