PT-2026-30701 · Totolink · Totolink A7100Ru

Ltzhuster2

·

Published

2026-03-29

·

Updated

2026-04-28

·

CVE-2026-5677

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Totolink A7100RU version 7.4cu.2313 b20191024
Description A security flaw exists in the CsteSystem function of the /cgi-bin/cstecgi.cgi file in Totolink A7100RU version 7.4cu.2313 b20191024. Manipulation of the resetFlags argument can lead to operating system command injection. The attack can be initiated remotely, and an exploit has been publicly released.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /cgi-bin/cstecgi.cgi file.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05257
CVE-2026-5677

Affected Products

Totolink A7100Ru