CVE-2026-1547 carries a CVSS 3.1 base score of 6.3 against TOTOLINK A7000R router firmware version 4.1cu.4154. NVD classifies it as CWE-74/CWE-77 (Injection/Command Injection). VulnCheck’s KEV feed reports the CVE as exploited, dated September 1, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-1547 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, the flaw affects a function in the router’s cstecgi.cgi binary responsible for unloading stored user configuration data. A request parameter representing a plugin name is passed into that function without adequate sanitization, and manipulating it results in command injection. NVD states the attack can be launched remotely and that this flaw has already been publicly disclosed with working reproduction material.
Evidence and confidence
- Medium confidence — the CVSS 6.3 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L), the CWE-74/CWE-77 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a VulDB catalog entry. The exploitation report traces to VulnCheck KEV alone. - High exploitation probability — FIRST’s EPSS model scores this CVE at 0.0288, an 86.2nd percentile score as of our ingestion.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field.
Why this matters
This is the second TOTOLINK command-injection flaw we’ve covered in this batch of KEV additions, following CVE-2025-60702 in the A950RG model — different products, different vulnerable functions, but the same underlying pattern of unsanitized request parameters reaching a system-command call in cstecgi.cgi-family firmware binaries. That recurrence across models and CVEs points to a systemic input-validation gap in how TOTOLINK’s shared CGI codebase handles configuration parameters, not an isolated one-off bug. Owners of TOTOLINK A7000R routers should check for a firmware update and, in the interim, keep the router’s management interface off the public internet.
Frequently Asked Questions
What is CVE-2026-1547? A CVSS 6.3 command injection vulnerability (CWE-74/CWE-77) in TOTOLINK A7000R router firmware 4.1cu.4154, reachable through the router’s CGI interface via an unsanitized plugin-name parameter.
Is CVE-2026-1547 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 1, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this?
NVD’s CVSS vector indicates low privileges are required (PR:L), meaning some existing, low-level access to the router’s management interface is necessary — though NVD also states the attack can be launched remotely.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Our source data does not carry a fixed-version field. Consult TOTOLINK’s own site for firmware update availability for the A7000R model.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-1547, corroborated by VulDB’s catalog entry. Exploitation status and the September 1, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.