References https://github.com/zxsssd/TotoLink- https://www.vulncheck.com/advisories/totolink-routers-authenticated-command-injection-via-cstecgi-cgi https://nvd.nist.gov/vuln/detail/CVE-2026-7240 https://www.ithome.com.tw/news/168560 https://www.anquanke.com/post/id/306930 https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/ https://stack.chaitin.com/vuldb/detail/0e342355-61ef-4a07-adda-17a1f4c60e79 https://www.fortinet.com/blog/threat-research/new-rust-bot-rustobot-is-routed-via-routers https://avd.aliyun.com/detail?id=AVD-2024-10966 https://cve.imfht.com/detail/CVE-2025-1340 https://www.iotsec-zone.com/article/106 https://www.anquanke.com/post/id/282739 https://cloud.tencent.com/developer/article/2206071 https://wkr.moe/study/853.html https://bbs.kanxue.com/thread-273945.htm https://app.opencve.io/cve/?vendor=totolink https://nvd.nist.gov/vuln/detail/CVE-2025-52906 https://github.com/Litengzheng/vuldb_new2/blob/main/A8000RU/vul_324/README.md
Related VulnerabilitiesPoCCVE-2026-19900: LB-LINK Routers - Unauthenticated Command InjectionPoCBLINK Routers /goform/set_cmd 命令执行漏洞(CVE-2025-1609)TOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞BLINK routers /goform/set_hidessid_cfg 命令执行漏洞(CVE-2025-45985)PoCCVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information DisclosurePoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassBLINK routers set_AdvDns_cfg 命令执行漏洞PoCCVE-2016-6277: NETGEAR Routers - Remote Code ExecutionPoCCVE-2017-15647: FiberHome Routers - Local File Inclusion