CVE-2026-5997

CRITICAL

Totolink A7100RU CGI cstecgi.cgi setLoginPasswordCfg os command injection

Title source: cna

Description

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

Scores

CVSS v3 9.8
EPSS 0.0125
EPSS Percentile 79.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
Totolink/A7100RU 7.4cu.2313_b20191024
Published Apr 10, 2026
Tracked Since Apr 10, 2026