Totolink A8000RU
Published Atomicorp research notes for CVEs affecting Totolink A8000RU where WAF protections were observed during testing or engineering review.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
| CVE | Vulnerability | CVSS | Severity | Rules Observed |
|---|---|---|---|---|
| CVE-2026-7202 | Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-7203 | Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-7204 | Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9384 | Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9385 | Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-9386 | Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9387 | Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9388 | Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9404 | Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9405 | Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9406 | Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9407 | Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9408 | Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection | 8.9 (v4.0) | High | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9432 | Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9433 | Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9434 | Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9435 | Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9436 | Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9454 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9455 | Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9456 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9457 | Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9458 | Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9475 | Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection | 8.9 (v4.0) | High | 340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-9476 | Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9477 | Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9478 | Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection | 8.9 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |