CVE-2026-5852: Totolink A7100RU CGI cstecgi.cgi setIptvCfg os command injection
A weakness has been identified in Totolink A7100RU 7.4cu.2313b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5852?
CVE-2026-5852 has been classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-5852?
To fix CVE-2026-5852, update the Totolink A7100RU firmware to a version that addresses this command injection vulnerability.
What is the impact of CVE-2026-5852?
The impact of CVE-2026-5852 allows an attacker to execute arbitrary OS commands on the affected Totolink A7100RU device.
Which devices are affected by CVE-2026-5852?
CVE-2026-5852 affects the Totolink A7100RU running firmware version 7.4cu.2313_b20191024.
How does CVE-2026-5852 exploit the system?
CVE-2026-5852 exploits the system through the manipulation of the igmpVer argument in the setIptvCfg function, leading to command injection.