<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>NR1800X (9.1.0u.6681_B20230703) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nr1800x-9.1.0u.6681_b20230703/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 03:13:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nr1800x-9.1.0u.6681_b20230703/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in TOTOLINK NR1800X</title><link>https://feed.craftedsignal.io/briefs/2026-08-totolink-command-injection/</link><pubDate>Mon, 31 Aug 2026 03:13:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-totolink-command-injection/</guid><description>The TOTOLINK NR1800X router is vulnerable to remote command injection via the setUssd function in cgi-bin/cstecgi.cgi, enabling unauthenticated attackers to execute arbitrary system commands.</description><content:encoded>&lt;p>A command injection vulnerability, tracked as CVE-2026-82597, exists in the TOTOLINK NR1800X router running firmware version 9.1.0u.6681_B20230703. The vulnerability originates within the setUssd function of the /cgi-bin/cstecgi.cgi script. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request with a malicious payload injected into the ussd parameter.&lt;/p>
&lt;p>Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the web server process on the affected router. Given the availability of public exploit code, the risk of exploitation by opportunistic actors is elevated. This vulnerability is critical for network perimeter security, as routers are common gateways. Defenders should note that this vulnerability does not require prior authentication, making it particularly dangerous for internet-facing devices.&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>command-injection</category><category>network-infrastructure</category></item></channel></rss>