OS Command Injection in Totolink A7100RU Product
CVE-2026-5689
Key Information:
Badges
What is CVE-2026-5689?
A vulnerability has been identified in the Totolink A7100RU firmware version 7.4cu.2313_b20191024, specifically within the setNtpCfg function of the cgi-bin/cstecgi.cgi file. This issue arises from improper handling of the 'tz' argument, allowing attackers to perform OS command injection. Such manipulation could lead to unauthorized remote access and exploitation of the system. As the exploit is now public, it emphasizes the critical need for affected users to review their security measures promptly.
Affected Version(s)
A7100RU 7.4cu.2313_b20191024
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
