PT-2026-30701 · Totolink · Totolink A7100Ru

·

CVE-2026-5677

·

Published

2026-03-29

·

Updated

2026-07-20

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Totolink A7100RU version 7.4cu.2313 b20191024
Description A security flaw exists in the CsteSystem function of the /cgi-bin/cstecgi.cgi file in Totolink A7100RU version 7.4cu.2313 b20191024. Manipulation of the resetFlags argument can lead to operating system command injection. The attack can be initiated remotely, and an exploit has been publicly released.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /cgi-bin/cstecgi.cgi file.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05257
CVE-2026-5677

Affected Products

Totolink A7100Ru