CVE-2026-5996: Totolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow os command injection
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313b20191024. The affected element is the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument ttyserver leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5996?
CVE-2026-5996 is classified as a high-severity vulnerability due to potential exploitation through OS command injection.
How do I fix CVE-2026-5996?
To fix CVE-2026-5996, you should update the Totolink A7100RU firmware to the latest version provided by the vendor.
Which product is affected by CVE-2026-5996?
CVE-2026-5996 affects the Totolink A7100RU router running version 7.4cu.2313_b20191024.
What type of vulnerability is CVE-2026-5996?
CVE-2026-5996 is an OS command injection vulnerability found in the CGI handler of the affected device.
What component of the Totolink A7100RU is vulnerable in CVE-2026-5996?
The vulnerable component in CVE-2026-5996 is the setAdvancedInfoShow function in the /cgi-bin/cstecgi.cgi file.