CVE-2026-5678: Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection
A weakness has been identified in Totolink A7100RU 7.4cu.2313b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5678?
The severity of CVE-2026-5678 is considered critical due to the potential for remote code execution via OS command injection.
How do I fix CVE-2026-5678?
To fix CVE-2026-5678, update the Totolink A7100RU firmware to the latest version provided by the vendor.
Which versions of Totolink A7100RU are affected by CVE-2026-5678?
CVE-2026-5678 affects the Totolink A7100RU version 7.4cu.2313_b20191024.
What types of attacks can CVE-2026-5678 facilitate?
CVE-2026-5678 can facilitate OS command injection attacks that may allow unauthorized command execution on the device.
Is CVE-2026-5678 publicly known?
Yes, CVE-2026-5678 is a publicly disclosed vulnerability, making it essential for users to address it promptly.