CVE-2026-7823General

MEDIUMCVSS 8.9 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • General: 5 classified signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 6 mentions (2026-05-15); latest day: 1
  • 12 total mentions across 4 days

Deep dive

Activity timeline12 mentions / 4d
02356Mentions · 2026-05-05: 4Mentions · 2026-05-12: 1Mentions · 2026-05-15: 6Mentions · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-16: 1Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-05: 3Technical Details · 2026-05-15: 4Technical Details · 2026-05-16: 105-0505-1205-1505-16
Signal classification5 categories
General
541.7%
Disclosure
433.3%
Patch
18.3%
Active Exploitation
18.3%
Exploit
18.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-054
Disclosure3Patch1
2026-05-121
Active Exploitation1
2026-05-156
Disclosure1General5
2026-05-161
Exploit1
Full discourse12 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Totolink A8000RU (CVE-2026-7823) https://vuldb.com/vuln/361075/cti

    Post summary

    CTI team reports widespread targeting of Totolink A8000RU via CVE‑2026‑7823, indicating active exploitation but no additional technical or mitigation details are provided.

    02010115
    2.2K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-7823 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post simply references a critical CVE with its CVSS score but otherwise lacks details on exploitation, patches, or PoC.

    1000032
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-7823 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text lists a critical CVE with its CVSS score and severity but offers no PoC, exploit, or patch details.

    1000031
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7823 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A security flaw has been discovered in Totolink A8000RU 7.1cu.643b20200521.

    Post summary

    The text announces a critical vulnerability (CVE‑2026‑7823) in Totolink A8000RU routers, providing CVSS metrics but no PoC, exploit details, or patch information.

    1000034
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-7823 (CVSS 9.8) — multiple products. CVE: CVE-2026-7823 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory signals a critically scored CVE-2026-7823 with no additional details on patches, exploits, or active use.

    1000028
    215 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7823 — CVSS 9.8/10 ██████████ A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/vgXA1aWh0n

    Post summary

    CVE-2026-7823 is a critical vulnerability in Totolink A8000RU, with a patch now available; no PoC, exploitation, or false‑positive claim was reported.

    1000041
    26 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7823 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation… https://www.cve.org/CVERecord?id=CVE-2026-7823

    Post summary

    The text announces the discovery of CVE-2026-7823 in a Totolink router firmware, noting a flaw in the setAppFilterCfg function, with a link to the CVE record for further details.

    00010165
    57.4K followersView on X
  • ADK Cyber@ADKCyber
    Exploit

    A critical OS command injection flaw (CVE-2026-7823) affects Totolink A8000RU routers. With a public exploit released, businesses should urgently update or isolate these devices to prevent remote attacks. Stay proactive in securing your network. #Cybersecurity

    Post summary

    CVE-2026-7823 is a critical OS command injection flaw in Totolink A8000RU routers with a publicly released exploit; users are urged to update or isolate devices to prevent remote attacks.

    0000060
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7823-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The message links to an advisory for CVE‑2026‑7823 but offers no explicit information about PoC, exploitation, patches, technical specifics, or false positive claims.

    0000025
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7823-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post advertises a CVE advisory via a link and hashtags but offers no substantive technical, exploit, or patch information.

    0000022
    215 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7823 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation… https://www.cve.org/CVERecord?id=CVE-2026-7823 ----- Traducción: CVE-2026-7823 Se … http://infoflow.cloud`

    Post summary

    The announcement reports a CVE affecting the Totolink A8000RU's setAppFilterCfg function, providing brief technical details but no PoC, exploit, or patch information.

    0000029
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7823 Remote Command Injection in Totolink A8000RU 7.1cu.643_b20200521 setAppFilterCfg https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7823

    Post summary

    The entry lists CVE-2026-7823 as a remote command injection flaw in Totolink firmware, without indicating a PoC, exploit tool, active exploitation, or patch.

    0000036
    4.0K followersView on X

Explore more