CVE-2026-9405Patch

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-27: 105-27
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • PurpleOps@PurpleOps_io
    Patch

    5 Critical CVEs to Fix Now - Totolink A8000RU, Lumiverse, DIAView Affected: Totolink A8000RU Web Management Interface; Lumiverse; FACTION; DIAView Today’s critical CVEs span networking gear and AI platform components, with several exploitable remotely. - CVE-2026-44450 (CVSS 9.9) Lumiverse MCP server creation endpoint forwards unvalidated args to a child process, enabling OS command execution by authenticated users on affected versions prior to 0.9.7. - CVE-2026-9405 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface setGameSpeedCfg allows OS command injection when enable is manipulated; remote. - CVE-2026-9406 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface setRemoteCfg manipulation of enable leads to OS command injection; remote. - CVE-2026-9642 (CVSS 9.8) DIAView project suffers an authentication bypass enabling unauthenticated remote access to configured databases due to an incomplete mitigation of CVE-2025-62582. - CVE-2026-44668 (CVSS 9.8) FACTION's AccessControlInterceptor permits unauthenticated access to boilerplate templates due to missing session checks; attackers can read, overwrite, deactivate, or purge templates; fixed in 1.8.3. Action - Patch/upgrade to fixed versions called out (Lumiverse 0.9.7; FACTION 1.8.3; apply vendor advisory latest for DIAView and Totolink). - Prioritize internet-facing Totolink A8000RU devices and other publicly exposed endpoints. - If no fix yet, apply vendor-recommended mitigations (restrict access to DIAView components; disable exposed features where feasible). - Add detections for exploitation patterns implied by the CVEs (process spawning from cstecgi.cgi; unusual enable parameter values; remote command patterns). - Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) focusing on /cgi-bin/cstecgi.cgi activities. - Validate remediation (version checks, config verification) and monitor for reversion or new attempts.

    Post summary

    The post lists five critical CVEs, details their impacts, and calls for immediate patching and mitigations.

    00010287
    575 followersView on X

Explore more