Junglewise Threat Intelligence

CVE-2026-82597: TOTOLINK NR1800X command injection in setUssd

CVE-2026-82597 · Severity: high · CVSS 7.4 · Published 2026-08-31

Technologies: TOTOLINK Nr1800x. Vendors: TOTOLINK.

Executive brief

TOTOLINK NR1800X is a router used to provide network connectivity. A vulnerability in its web management interface allows an attacker to inject arbitrary system commands through the setUssd function, potentially gaining remote control of the device and access to network traffic or connected systems.

Technical details

A command injection vulnerability exists in the setUssd function of /cgi-bin/cstecgi.cgi in TOTOLINK NR1800X firmware version 9.1.0u.6681_B20230703. The vulnerability arises from insufficient input validation on the ussd parameter, allowing an attacker to inject arbitrary shell commands that are executed with device privileges. The attack is network-accessible and does not require authentication. Successful exploitation grants remote code execution on the affected router, potentially compromising network security and customer data. An exploit is publicly available.

Affected products

  • TOTOLINK NR1800X 9.1.0u.6681_B20230703

Timeline

  • 2026-08-31: disclosed
  • other: exploit publicly available

References

Related threats