CVE-2026-1623Disclosure(totolink / a7000r)

MEDIUMCVSS 2.1 · LOW

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch totolink a7000r systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • a7000r
  • a7000r_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-30)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
a7000ra7000r_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-01-29: 1Mentions · 2026-01-30: 1Mentions · 2026-02-10: 1Mentions · 2026-07-30: 2PoC Mentioned / Linked · 2026-07-30: 1Active Exploitation · 2026-07-30: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-01-29: 1Technical Details · 2026-01-30: 101-2901-3002-1007-30
Signal classification4 categories
Disclosure
240.0%
Patch
120.0%
Active Exploitation
120.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-291
Disclosure1
2026-01-301
Disclosure1
2026-02-101
Patch1
2026-07-302
Active Exploitation1General1
Full discourse5 posts
  • KEVIntel@kev_intel
    Active Exploitation

    KEVIntel sensors observed an exploitation attempt against TOTOLINK A7000R CVE-2026-1623. A public PoC has existed since January. CVSS lists PR, yet neither the PoC nor the observed request used authentication. The PR rating may be incorrect.

    Post summary

    KEVIntel sensors detected an active exploitation attempt targeting TOTOLINK A7000R’s CVE-2026-1623, while a public PoC has existed since January but authentication was not required.

    10010124
    44 followersView on X
  • KEVIntel@kev_intel
    General

    https://kevintel.com/CVE-2026-1623#sensor-telemetry

    Post summary

    The text provides no substantive information about CVE-2026-1623, offering only a URL without accompanying details.

    0000057
    44 followersView on X
  • Grok@grok
    Patch

    En 2026, se han reportado múltiples vulnerabilidades por defecto en routers caseros, como credenciales predeterminadas en Four-Faith (afectando >15.000 dispositivos), CVE-2026-1623 en Totolink A7000R, CVE-2026-0834 en TP-Link Archer, y fallos en NETGEAR Orbi y chipsets Broadcom. No hay un conteo exacto fijo, ya que surgen continuamente. Recomiendo actualizar firmware, cambiar contraseñas default y usar firewalls fuertes para minimizar riesgos.

    Post summary

    The post lists multiple router vulnerabilities, including default‑credential issues and CVE‑2026‑1623/0834, and advises users to update firmware, reset passwords, and employ firewalls to reduce risk.

    0000052
    8.1M followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1623 Command Injection in Totolink A7000R 4.1cu.4154 via Firmware Upgrade Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1623

    Post summary

    CVE-2026-1623 is a command injection vulnerability in the firmware upgrade function of the Totolink A7000R, allowing attackers to execute arbitrary commands on the device.

    0000093
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1623 A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument … https://www.cve.org/CVERecord?id=CVE-2026-1623

    Post summary

    A vulnerability was disclosed in the Totolink A7000R's upgrade function, with no PoC, exploit, active exploitation, or patch mentioned.

    00000238
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtotolinka7000r---
OStotolinka7000r_firmware4.1cu.4154--

Explore more