PT-2026-36751 · Totolink · Wa300

Wxhwxhwxh_Mie

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-7721

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A security vulnerability has been detected in Totolink WA300 5.2cu.7112 B20190227. This affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument hostTime leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

Exploit

Fix

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7721

Affected Products

Wa300