CVE-2026-5854: Totolink A7100RU CGI cstecgi.cgi setWiFiEasyCfg os command injection
A vulnerability was detected in Totolink A7100RU 7.4cu.2313b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument merge results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5854?
CVE-2026-5854 is considered a high severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2026-5854?
To fix CVE-2026-5854, upgrade the Totolink A7100RU firmware to the latest version available from the manufacturer.
What component is affected by CVE-2026-5854?
CVE-2026-5854 affects the CGI Handler component, specifically the setWiFiEasyCfg function in the cstecgi.cgi file.
What type of attack can exploit CVE-2026-5854?
CVE-2026-5854 can be exploited through OS command injection attacks that manipulate the argument in the vulnerable function.
Which version of Totolink A7100RU is vulnerable to CVE-2026-5854?
Only the Totolink A7100RU version 7.4cu.2313_b20191024 is directly affected by CVE-2026-5854.