{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nr1800x-9.1.0u.6681_b20230703/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:totolink:nr1800x:9.1.0u.6681_b20230703:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-82597"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NR1800X (9.1.0u.6681_B20230703)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","command-injection","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["TOTOLINK"],"content_html":"\u003cp\u003eA command injection vulnerability, tracked as CVE-2026-82597, exists in the TOTOLINK NR1800X router running firmware version 9.1.0u.6681_B20230703. The vulnerability originates within the setUssd function of the /cgi-bin/cstecgi.cgi script. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request with a malicious payload injected into the ussd parameter.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation allows the attacker to execute arbitrary commands with the privileges of the web server process on the affected router. Given the availability of public exploit code, the risk of exploitation by opportunistic actors is elevated. This vulnerability is critical for network perimeter security, as routers are common gateways. Defenders should note that this vulnerability does not require prior authentication, making it particularly dangerous for internet-facing devices.\u003c/p\u003e\n","date_modified":"2026-08-31T03:13:32Z","date_published":"2026-08-31T03:13:32Z","id":"https://feed.craftedsignal.io/briefs/2026-08-totolink-command-injection/","summary":"The TOTOLINK NR1800X router is vulnerable to remote command injection via the setUssd function in cgi-bin/cstecgi.cgi, enabling unauthenticated attackers to execute arbitrary system commands.","title":"Remote Command Injection in TOTOLINK NR1800X","url":"https://feed.craftedsignal.io/briefs/2026-08-totolink-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - NR1800X (9.1.0u.6681_B20230703)","version":"https://jsonfeed.org/version/1.1"}