CVE-2026-5993: Totolink A7100RU CGI cstecgi.cgi setWiFiGuestCfg os command injection
A vulnerability was identified in Totolink A7100RU 7.4cu.2313b20191024. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wifiOff leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5993?
CVE-2026-5993 is classified as a high-severity vulnerability due to its potential for os command injection.
How do I fix CVE-2026-5993?
To mitigate CVE-2026-5993, update the Totolink A7100RU firmware to the latest version provided by the manufacturer.
What product is affected by CVE-2026-5993?
CVE-2026-5993 affects the Totolink A7100RU version 7.4cu.2313_b20191024.
What type of vulnerability is CVE-2026-5993?
CVE-2026-5993 is an os command injection vulnerability present in the CGI handler of the affected device.
Which component is exploited in CVE-2026-5993?
CVE-2026-5993 exploits the function setWiFiGuestCfg within the /cgi-bin/cstecgi.cgi file.