CVE-2026-5030

MEDIUM

Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection

Title source: cna
STIX 2.1

Description

A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 6.3
EPSS 0.0192
EPSS Percentile 83.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-77
Status published
Products (2)
Totolink/NR1800X 9.1.0u.6279_B20210910
totolink/nr1800x_firmware 9.1.0u.6279_b20210910
Published Mar 29, 2026
Tracked Since Mar 29, 2026