References https://github.com/zxsssd/TotoLink- https://www.ithome.com.tw/news/168560 https://www.iotsec-zone.com/article/317 https://nvd.nist.gov/vuln/detail/CVE-2026-7240 https://avd.aliyun.com/detail?id=AVD-2024-10966 https://www.cnvd.org.cn/flaw/show/CNVD-2024-44851 https://www.anquanke.com/post/id/282739 https://cve.imfht.com/detail/CVE-2025-1340 https://app.opencve.io/cve/?vendor=totolink https://www.cnvd.org.cn/flaw/show/CNVD-2026-00121 https://cve.imfht.com/intel/590767 https://www.vulncheck.com/advisories/totolink-routers-authenticated-command-injection-via-cstecgi-cgi https://www.cnvd.org.cn/flaw/show/CNVD-2026-18804 https://www.cnvd.org.cn/flaw/show/CNVD-2026-00123 https://www.cnvd.org.cn/flaw/show/CNVD-2026-16680 https://github.com/Objia/Vulnerability_analysis_reproduction/blob/master/TOTOLINK%20N200RE%E7%99%BB%E5%BD%95%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%E5%92%8C%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90.md https://github.com/emadshanab/goby-poc/blob/main/TotoLink-FileName-RCE(CVE-2022-26210).json
Related VulnerabilitiesTOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞PoCCVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information DisclosurePoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-42887: TOTOLINK EX1200T 4.1.2cu.5215 - Authentication BypassPoCCVE-2022-25082: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-30013: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-46574: TOTOLINK A3700R - Command InjectionPoCCVE-2024-24328: TotoLink Router setMacFilterRules - Command InjectionPoCCVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection