CVE-2026-5850: Totolink A7100RU CGI cstecgi.cgi setVpnPassCfg os command injection
A vulnerability was identified in Totolink A7100RU 7.4cu.2313b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5850?
CVE-2026-5850 has been classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-5850?
To mitigate CVE-2026-5850, it is recommended to upgrade the Totolink A7100RU firmware to the latest version provided by the vendor.
What is affected by CVE-2026-5850?
CVE-2026-5850 specifically affects the Totolink A7100RU version 7.4cu.2313_b20191024.
What type of vulnerability is CVE-2026-5850?
CVE-2026-5850 is an OS command injection vulnerability found in the CGI handler of the Totolink A7100RU.
Can CVE-2026-5850 be exploited remotely?
Yes, CVE-2026-5850 can be exploited remotely by manipulating specific arguments in the vulnerable CGI script.