Totolink · Nr1800X · CVE-2026-82597
**Name of the Vulnerable Software and Affected Versions**
TOTOLINK NR1800X version 9.1.0u.6681 B20230703
**Description**
A remote command injection issue exists in the `/cgi-bin/cstecgi.cgi` endpoint. The flaw occurs within the `setUssd()` function when processing the `ussd` variable, allowing an attacker to execute arbitrary commands on the system.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `/cgi-bin/cstecgi.cgi` endpoint or avoid using the `ussd` parameter.