PT-2026-31852 · Totolink · Totolink A7100Ru

Ltzhust

·

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-5996

CVSS v2.0

10

Critical

AV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Totolink A7100RU version 7.4cu.2313 b20191024
Description A security issue exists in the Totolink A7100RU router. The setAdvancedInfoShow function within the CGI Handler component, specifically in the file /cgi-bin/cstecgi.cgi, is susceptible to OS command injection. This occurs through manipulation of the tty server argument. The attack can be initiated remotely. The exploit has been publicly disclosed.
Recommendations For Totolink A7100RU version 7.4cu.2313 b20191024, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5996

Affected Products

Totolink A7100Ru