CVE-2026-5030: Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection
A vulnerability has been found in Totolink NR1800X 9.1.0u.6279B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument hosttime leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5030?
The severity of CVE-2026-5030 is critical due to the potential for command injection through the NTPSyncWithHost function.
How do I fix CVE-2026-5030?
To fix CVE-2026-5030, update the Totolink NR1800X firmware to the latest available version that addresses this vulnerability.
What systems are affected by CVE-2026-5030?
CVE-2026-5030 affects the Totolink NR1800X with firmware version 9.1.0u.6279_B20210910.
What is the impact of CVE-2026-5030?
The impact of CVE-2026-5030 allows attackers to execute arbitrary commands on the Telnet service via a crafted NTPSyncWithHost command.
Is CVE-2026-5030 exploitable remotely?
Yes, CVE-2026-5030 is exploitable remotely since it involves a vulnerability in the Telnet service accessible over the network.