CVE-2026-5020: Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection
A vulnerability was detected in Totolink A3600R 4.1.2cu.5182B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5020?
CVE-2026-5020 is considered a critical vulnerability due to its potential for command injection.
How do I fix CVE-2026-5020?
To fix CVE-2026-5020, you should update the Totolink A3600R firmware to the latest version available.
What component is affected by CVE-2026-5020?
CVE-2026-5020 affects the Parameter Handler component, specifically the setNoticeCfg function in the /cgi-bin/cstecgi.cgi file.
Which version of Totolink A3600R is impacted by CVE-2026-5020?
The affected version of Totolink A3600R is 4.1.2cu.5182_B20201102.
What type of vulnerability is CVE-2026-5020?
CVE-2026-5020 is a command injection vulnerability that allows an attacker to execute arbitrary commands.