CVE-2026-7202Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument wscDisabled leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-28); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-04-28: 3Mentions · 2026-04-29: 3Mentions · 2026-05-25: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 304-2804-2905-25
Signal classification3 categories
Disclosure
342.9%
General
228.6%
Patch
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-283
Disclosure1General1Patch1
2026-04-293
Disclosure2Patch1
2026-05-251
General1
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7202 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI … https://www.cve.org/CVERecord?id=CVE-2026-7202

    Post summary

    The text announces a vulnerability in the Totolink A8000RU router that affects the setWiFiWpsStart function but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00010180
    57.3K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7202 — CVSS 9.8/10 ██████████ A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/OJ0NmxW2mp

    Post summary

    CVE-2026-7202 is a critical vulnerability (CVSS 9.8) affecting Totolink A8000RU, with a patch now available. No proof of concept, exploit, or active exploitation details are provided.

    1000051
    27 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-04-28-totolink-a8000ru-cve-2026-7202-rce #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet simply shares a link and hashtags about a CVE without providing any PoC, exploit, patch information, or detailed vulnerability description.

    0000030
    227 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7202 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI … https://www.cve.org/CVERecord?id=CVE-2026-7202 ----- Traducción: Se ha encontrado … http://infoflow.cloud`

    Post summary

    The post announces a new vulnerability (CVE-2026-7202) affecting the Totolink A8000RU router, detailing the vulnerable function but providing no PoC, exploit code, or mitigation steps.

    0000025
    74 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: IoT & Cloud Stack (CVSS 9.8-9.8) Affected: Milesight AIOT; NVIDIA NVFlare Dashboard; Totolink A8000RU CGI Handler Internet-facing risks dominate, led by IoT devices and cloud platforms; fixes and mitigations below. • CVE-2026-32644 (CVSS 9.8) Milesight AIOT cameras with affected firmware versions use SSL certificates with default private keys. • CVE-2026-24178 (CVSS 9.8) NVIDIA NVFlare Dashboard (unspecified versions) contains unauthenticated authorization bypass via a user-controlled key. • CVE-2026-7202 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setWiFiWpsStart allows remote OS command injection via wscDisabled. • CVE-2026-7203 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setUrlFilterRules allows remote OS command injection via enable parameter. • CVE-2026-7204 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setPptpServerCfg allows remote OS command injection via enable parameter. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The announcement focuses on high‑CVSS IoT and cloud vulnerabilities and urges immediate patching and mitigation, with no PoC, exploit, or active exploitation evidence provided.

    0000057
    100 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7202 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7202 #CVE-2026-7202 #CVE #Critical #CyberSecurity #InfoSec https://t.co/Yo2FrYrv6z

    Post summary

    The tweet announces CVE-2026-7202 with a severity rating but provides no technical, exploit, or patch information.

    0000054
    142 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7202 Remote OS Command Injection in Totolink A8000RU 7.1cu.643_b2020052... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7202 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-7202, a remote OS command injection vulnerability affecting Totolink A8000RU routers, and provides a link to detailed information.

    0000036
    4.0K followersView on X

Explore more