CVE-2026-5851: Totolink A7100RU CGI cstecgi.cgi setUPnPCfg os command injection
A security flaw has been discovered in Totolink A7100RU 7.4cu.2313b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5851?
CVE-2026-5851 is classified as a high severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2026-5851?
To mitigate CVE-2026-5851, it's recommended to update the Totolink A7100RU firmware to the latest version that addresses this specific vulnerability.
What impact does CVE-2026-5851 have on affected systems?
CVE-2026-5851 allows remote attackers to execute arbitrary OS commands on the affected device via manipulated CGI parameters.
Which devices are affected by CVE-2026-5851?
CVE-2026-5851 specifically affects the Totolink A7100RU with firmware version 7.4cu.2313_b20191024.
What component is vulnerable in CVE-2026-5851?
The vulnerability in CVE-2026-5851 resides in the CGI Handler, particularly in the setUPnPCfg function of the cstecgi.cgi file.