CVE-2026-5977: Totolink A7100RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
A weakness has been identified in Totolink A7100RU 7.4cu.2313b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wifiOff can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5977?
CVE-2026-5977 is categorized as a high severity vulnerability due to the potential for remote code execution via OS command injection.
How do I fix CVE-2026-5977?
To fix CVE-2026-5977, update the firmware of the Totolink A7100RU to a version that addresses this vulnerability.
What components are affected by CVE-2026-5977?
CVE-2026-5977 affects the CGI Handler function setWiFiBasicCfg in the cstecgi.cgi file on the Totolink A7100RU.
What type of vulnerability is CVE-2026-5977?
CVE-2026-5977 is an OS command injection vulnerability that allows an attacker to execute arbitrary commands on affected devices.
When was CVE-2026-5977 disclosed?
CVE-2026-5977 was disclosed related to the Totolink A7100RU version 7.4cu.2313_b20191024.