CVE-2026-5677

HIGH

Totolink A7100RU cstecgi.cgi CsteSystem os command injection

Title source: cna

Description

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

Scores

CVSS v3 7.3
EPSS 0.0486
EPSS Percentile 89.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
Totolink/A7100RU 7.4cu.2313_b20191024
Published Apr 06, 2026
Tracked Since Apr 07, 2026