PatchDay Alert

CVE

CVE-2026-7122

0field notes · 1digest CVSS 9.8


Daily digests

An attacker can inject OS commands remotely through the UPnP configuration handler on Totolink A8000RU routers running firmware 7.1cu.643_b20200521. No authentication is needed, and a public exploit already exists. CVSS 9.8, so this is full remote takeover of the device.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.