CVE-2026-5689: Totolink A7100RU cstecgi.cgi setNtpCfg os command injection
A vulnerability was detected in Totolink A7100RU 7.4cu.2313b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument tz results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5689?
CVE-2026-5689 has a high severity rating due to the potential for remote command injection.
How do I fix CVE-2026-5689?
The fix for CVE-2026-5689 involves updating the affected Totolink A7100RU device to the latest firmware version.
What systems are affected by CVE-2026-5689?
CVE-2026-5689 affects the Totolink A7100RU running firmware version 7.4cu.2313_b20191024.
What type of vulnerability is CVE-2026-5689?
CVE-2026-5689 is classified as an OS command injection vulnerability.
Can CVE-2026-5689 be exploited remotely?
Yes, CVE-2026-5689 can be exploited remotely by manipulating the tz argument in the setNtpCfg function.