CVE-2026-5994: Totolink A7100RU CGI cstecgi.cgi setTelnetCfg os command injection
A security flaw has been discovered in Totolink A7100RU 7.4cu.2313b20191024. This issue affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument telnetenabled results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5994?
CVE-2026-5994 has a high severity rating due to its potential to allow unauthorized command execution.
How do I fix CVE-2026-5994?
To fix CVE-2026-5994, update the Totolink A7100RU firmware to a version that addresses this command injection vulnerability.
What components are affected by CVE-2026-5994?
CVE-2026-5994 affects the CGI Handler component of the Totolink A7100RU router, specifically the setTelnetCfg function.
Can CVE-2026-5994 lead to remote code execution?
Yes, CVE-2026-5994 allows attackers to potentially execute arbitrary OS commands remotely.
Is there a workaround for CVE-2026-5994 if I cannot update?
As a temporary workaround for CVE-2026-5994, consider disabling Telnet access on the Totolink A7100RU until a firmware update can be applied.