Skip to content
Threat Feed
high advisory

Remote Command Injection in TOTOLINK NR1800X

The TOTOLINK NR1800X router is vulnerable to remote command injection via the setUssd function in cgi-bin/cstecgi.cgi, enabling unauthenticated attackers to execute arbitrary system commands.

CVE search metadata

CVE search record: CVE-2026-82597. Severity: high. CVSS: 7.4. KEV: no. Product: NR1800X (9.1.0u.6681_B20230703). Brief: Remote Command Injection in TOTOLINK NR1800X. Brief link: https://feed.craftedsignal.io/briefs/2026-08-totolink-command-injection/

A command injection vulnerability, tracked as CVE-2026-82597, exists in the TOTOLINK NR1800X router running firmware version 9.1.0u.6681_B20230703. The vulnerability originates within the setUssd function of the /cgi-bin/cstecgi.cgi script. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request with a malicious payload injected into the ussd parameter.

Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the web server process on the affected router. Given the availability of public exploit code, the risk of exploitation by opportunistic actors is elevated. This vulnerability is critical for network perimeter security, as routers are common gateways. Defenders should note that this vulnerability does not require prior authentication, making it particularly dangerous for internet-facing devices.


Immediate actions

Block external access to cgi-bin/cstecgi.cgi

IT Operations 24h

Mitigations

Check for firmware updates from TOTOLINK

immediate IT Operations

CVE-2026-82597

Detection coverage 1

Detects CVE-2026-82597 Exploitation - Command Injection in cstecgi.cgi

high

Detects exploitation of CVE-2026-82597 via suspicious command injection characters in the ussd parameter of the /cgi-bin/cstecgi.cgi script.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →