CVE-2026-7037Disclosure

MEDIUMCVSS 8.9 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-05-24); latest day: 2
  • 9 total mentions across 3 days

Deep dive

Activity timeline9 mentions / 3d
01345Mentions · 2026-04-26: 2Mentions · 2026-05-24: 5Mentions · 2026-06-22: 2Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-06-22: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-04-26: 2Technical Details · 2026-05-24: 3Technical Details · 2026-06-22: 204-2605-2406-22
Signal classification4 categories
Disclosure
555.6%
General
222.2%
Patch
111.1%
Active Exploitation
111.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-262
Disclosure1Patch1
2026-05-245
Disclosure3General2
2026-06-222
Active Exploitation1Disclosure1
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Unpopular opinion: The cybersecurity industry is selling you dashboards. Totolink A8000RU Command Injection (CVE-2026-7037): The Router That Became a Botnet Entry Point

    Post summary

    The post notes that CVE‑2026‑7037 is a command injection in the Totolink A8000RU router and claims the device has become an entry point for botnet activity, but offers no PoC, exploit code, patches, or deep technical analysis.

    1000052
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources TheHackerWire: Totolink A8000RU Remote OS Command Injection (CVE-2026-7037) OffSeq Threat Radar: CVE-2026-7037 Live Threat Intelligence Totolink A8000RU: CVSS 9.8 Unauthenticated RCE Released to Public—No Patch Available

    Post summary

    CVE-2026-7037, a CVSS 9.8 unauthenticated remote OS command injection in Totolink A8000RU, has been publicly disclosed with no patch available, and live threat intelligence suggests active exploitation.

    1000058
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On April 26, 2026, security researchers disclosed CVE-2026-7037: a critical command injection flaw in the Totolink A8000RU wireless router firmware (version 7.1cu.643b20200521). The vulnerability exists in the /cgi-bin/cstecgi.cgi CGI handler, specifically within the…

    Post summary

    Researchers disclosed a critical command injection vulnerability in the Totolink A8000RU router, highlighting the affected CGI handler, but no PoC, exploit, patch, or active exploitation details were provided.

    1000047
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR A critical OS command injection vulnerability (CVE-2026-7037, CVSS 9.8) affecting Totolink A8000RU routers went public on April 26, 2026. Remote, unauthenticated attackers can execute arbitrary OS commands via malicious web requests—and a working exploit is already…

    Post summary

    The snippet announces the exposure of a critical OS command injection flaw (CVE‑2026‑7037) in Totolink routers, noting a high CVSS score and that an exploit already exists, but does not provide details on exploitation or mitigation.

    1000073
    227 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7037 — CVSS 9.8/10 ██████████ A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/SQQZReNXaT

    Post summary

    CVE-2026-7037 impacts Totolink A8000RU firmware with a critical CVSS score, but a patch has already been released.

    1000052
    27 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/totolink-a8000ru-cve-2026-7037-rce #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link references a research article on Totolink A8000RU CVE‑2026‑7037, an RCE vulnerability; no PoC, exploit tool, active exploitation, patch, or false‑positive claim is provided.

    0000028
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-04-27-totolink-a8000ru-cve-2026-7037 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post includes only a link and hashtags, without substantive details about CVE‑2026‑7037 or related mitigation.

    0000032
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-04-27-totolink-a8000ru-cve-2026-7037 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided reference cites a CVE (CVE‑2026‑7037) affecting Totolink A8000RU, but no further details, PoC, exploit code, patch information, or exploitation activity are disclosed.

    0000035
    227 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7037 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the compo… https://www.cve.org/CVERecord?id=CVE-2026-7037

    Post summary

    A new vulnerability (CVE-2026-7037) affecting the setVpnPassCfg function in Totolink routers has been disclosed, providing limited technical detail but no PoC, exploit, patch, or active exploitation reported.

    00000118
    57.3K followersView on X

Explore more