CVE-2026-7204Active Exploitation

MEDIUMCVSS 8.9 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-28); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-28: 2Mentions · 2026-04-29: 1Active Exploitation · 2026-04-28: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 104-2804-29
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-282
Active Exploitation1Disclosure1
2026-04-291
Patch1
Full discourse3 posts
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: IoT & Cloud Stack (CVSS 9.8-9.8) Affected: Milesight AIOT; NVIDIA NVFlare Dashboard; Totolink A8000RU CGI Handler Internet-facing risks dominate, led by IoT devices and cloud platforms; fixes and mitigations below. • CVE-2026-32644 (CVSS 9.8) Milesight AIOT cameras with affected firmware versions use SSL certificates with default private keys. • CVE-2026-24178 (CVSS 9.8) NVIDIA NVFlare Dashboard (unspecified versions) contains unauthenticated authorization bypass via a user-controlled key. • CVE-2026-7202 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setWiFiWpsStart allows remote OS command injection via wscDisabled. • CVE-2026-7203 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setUrlFilterRules allows remote OS command injection via enable parameter. • CVE-2026-7204 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setPptpServerCfg allows remote OS command injection via enable parameter. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post summarizes critical IoT and cloud CVEs with technical details and stresses the importance of applying vendor patches and mitigations.

    0000057
    100 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7204 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7204 #CVE-2026-7204 #CVE #Critical #CyberSecurity #InfoSec https://t.co/SPLXGveG11

    Post summary

    The tweet announces the new CVE‑2026‑7204 with a severity score of 9.8 and a critical risk level, but provides no technical, exploitation, or remediation details.

    0000048
    142 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CVE-2026-7204 in Totolink A8000RU routers is under active exploitation—attackers can execute arbitrary OS commands. Patch now to prevent unauthorized access and potential data breaches. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #ZeroTrust #Microsoft #Cisco https://t.co/6KBZ2jpvBr

    Post summary

    CVE‑2026‑7204 is actively exploited on Totolink A8000RU routers, enabling arbitrary OS command execution; a vendor patch is available to mitigate the threat.

    0000071
    57 followersView on X

Explore more