CVE-2026-5975: Totolink A7100RU CGI cstecgi.cgi setDmzCfg os command injection
A vulnerability was identified in Totolink A7100RU 7.4cu.2313b20191024. The impacted element is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wanIdx leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5975?
CVE-2026-5975 is classified as a high-severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2026-5975?
To fix CVE-2026-5975, you should update the Totolink A7100RU firmware to a version that addresses this vulnerability.
What are the potential impacts of CVE-2026-5975?
The potential impacts of CVE-2026-5975 include unauthorized access to the operating system and execution of arbitrary commands.
What versions of Totolink A7100RU are affected by CVE-2026-5975?
CVE-2026-5975 affects Totolink A7100RU version 7.4cu.2313_b20191024.
Is there a workaround for CVE-2026-5975?
Currently, the recommended solution for CVE-2026-5975 is to update to a patched firmware rather than relying on a workaround.