CyberRota
Back to database

CVE-2026-9436

CRITICAL · CVSS 9.8 EPSS 2.00% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-25 · Last synced: 2026-06-20

CyberRota Analysis

Uzaktan istismar edilebilir olabilir.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9436
Severity
CRITICAL
CVSS
9.8
EPSS
2.00%

Original NVD Description

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.