PT-2026-30750 · Totolink · A7100Ru

Ltzhust2

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-5689

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in Totolink A7100RU 7.4cu.2313 b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument tz results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5689

Affected Products

A7100Ru