Totolink A8000RU

Published Atomicorp research notes for CVEs affecting Totolink A8000RU where WAF protections were observed during testing or engineering review.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

CVEVulnerabilityCVSSSeverityRules Observed
CVE-2026-7202Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-7203Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-7204Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9384Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9385Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-9386Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9387Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9388Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9404Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9405Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9406Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9407Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9408Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection8.9 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9432Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9433Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9434Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9435Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9436Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9454Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9455Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9456Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9457Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9458Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9475Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection8.9 (v4.0)High340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-9476Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9477Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9478Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655