CVE-2026-1327

Source
https://cve.org/CVERecord?id=CVE-2026-1327
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1327.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1327
Published
2026-01-22T15:16:50.967Z
Modified
2026-03-13T04:01:22.035442Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Such manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1327.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.1.0u.6279_b20210910"
            }
        ]
    }
]