Description
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerable setUssd command allows an attacker to inject arbitrary shell commands into the operating system of the TOTOLINK NR1800X router when the ussd argument is not properly validated. This flaw permits the execution of malicious code, potentially compromising the confidentiality, integrity, and availability of the device and any connected networks.

Affected Systems

Products affected are TOTOLINK NR1800X routers running firmware version 9.1.0u.6681_B20230703. The flaw resides in the cstecgi.cgi executable exposed via the web interface.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. However, the attack can be carried out remotely with publicly available exploit code, making the risk moderate but significant enough to warrant timely remediation.

Generated by OpenCVE AI on August 31, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware update from TOTOLINK that fixes the setUssd command injection.
  • If a patch is not yet released, restrict remote access to the router’s web interface or disable the setUssd function via the management portal.
  • Implement network segmentation and firewall rules to block untrusted networks from reaching the router’s administration interface to reduce the attack surface.

Generated by OpenCVE AI on August 31, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink nr1800x
Vendors & Products Totolink nr1800x

Mon, 31 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Title TOTOLINK NR1800X cstecgi.cgi setUssd command injection
First Time appeared Totolink
Totolink nr1800x Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:totolink:nr1800x_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink nr1800x Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Totolink Nr1800x Nr1800x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T00:15:09.430Z

Reserved: 2026-08-30T06:27:13.531Z

Link: CVE-2026-82597

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T01:16:50.190

Modified: 2026-08-31T01:16:50.190

Link: CVE-2026-82597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T03:00:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')