PT-2026-30749 · Totolink · A7100Ru

Ltzhust2

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-5688

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313 b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5688

Affected Products

A7100Ru