Remote Command Injection in TOTOLINK NR1800X
The TOTOLINK NR1800X router is vulnerable to remote command injection via the setUssd function in cgi-bin/cstecgi.cgi, enabling unauthenticated attackers to execute arbitrary system commands.
CVE search metadata
CVE search record: CVE-2026-82597. Severity: high. CVSS: 7.4. KEV: no. Product: NR1800X (9.1.0u.6681_B20230703). Brief: Remote Command Injection in TOTOLINK NR1800X. Brief link: https://feed.craftedsignal.io/briefs/2026-08-totolink-command-injection/
A command injection vulnerability, tracked as CVE-2026-82597, exists in the TOTOLINK NR1800X router running firmware version 9.1.0u.6681_B20230703. The vulnerability originates within the setUssd function of the /cgi-bin/cstecgi.cgi script. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request with a malicious payload injected into the ussd parameter.
Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the web server process on the affected router. Given the availability of public exploit code, the risk of exploitation by opportunistic actors is elevated. This vulnerability is critical for network perimeter security, as routers are common gateways. Defenders should note that this vulnerability does not require prior authentication, making it particularly dangerous for internet-facing devices.
Immediate actions
Block external access to cgi-bin/cstecgi.cgi
Mitigations
Check for firmware updates from TOTOLINK
CVE-2026-82597
Detection coverage 1
Detects CVE-2026-82597 Exploitation - Command Injection in cstecgi.cgi
highDetects exploitation of CVE-2026-82597 via suspicious command injection characters in the ussd parameter of the /cgi-bin/cstecgi.cgi script.
Detection queries are available on the platform. Get full rules →