CVE-2026-7203Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-29)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-28: 2Mentions · 2026-04-29: 3Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 204-2804-29
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-282
Disclosure1Patch1
2026-04-293
Disclosure1General1Patch1
Full discourse5 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7203 — CVSS 9.8/10 ██████████ A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/hMAZsJFkQW

    Post summary

    The tweet announces the discovery of CVE-2026-7203, a critical vulnerability in Totolink routers, and urges users to apply the available patch.

    1000046
    25 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7203 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the com… https://www.cve.org/CVERecord?id=CVE-2026-7203 ----- Traducción: CVE-2026-7203 Se … http://infoflow.cloud`

    Post summary

    The post briefly cites CVE-2026-7203, noting an affected function in a firmware bin, but provides no actionable details on exploitation, fixes, or severity.

    0000025
    74 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7203 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the com… https://www.cve.org/CVERecord?id=CVE-2026-7203

    Post summary

    The statement announces that CVE-2026-7203 affects the Totolink A8000RU firmware via the setUrlFilterRules function in cstecgi.cgi, but provides no exploit, patch, or active exploitation information.

    00000177
    57.3K followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: IoT & Cloud Stack (CVSS 9.8-9.8) Affected: Milesight AIOT; NVIDIA NVFlare Dashboard; Totolink A8000RU CGI Handler Internet-facing risks dominate, led by IoT devices and cloud platforms; fixes and mitigations below. • CVE-2026-32644 (CVSS 9.8) Milesight AIOT cameras with affected firmware versions use SSL certificates with default private keys. • CVE-2026-24178 (CVSS 9.8) NVIDIA NVFlare Dashboard (unspecified versions) contains unauthenticated authorization bypass via a user-controlled key. • CVE-2026-7202 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setWiFiWpsStart allows remote OS command injection via wscDisabled. • CVE-2026-7203 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setUrlFilterRules allows remote OS command injection via enable parameter. • CVE-2026-7204 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setPptpServerCfg allows remote OS command injection via enable parameter. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post lists multiple high‑severity CVEs affecting IoT and cloud devices, provides detailed technical information, and emphasizes patching, mitigation, and monitoring actions.

    0000057
    100 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7203 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7203 #CVE-2026-7203 #CVE #Critical #CyberSecurity #InfoSec https://t.co/fJ5U7BtQya

    Post summary

    A new CVE-2026-7203 alert reports a 9.8 severity critical vulnerability affecting multiple products, but no PoC, exploit, or patch details are offered.

    0000056
    142 followersView on X

Explore more