Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
Totolink A7100RU Router Allows Remote Code Execution Through CGI Script
CVE-2026-5692
Summary
A security flaw in the Totolink A7100RU router's CGI script makes it possible for an attacker to execute unauthorized code on the router from a remote location. This could allow an attacker to take control of the router or disrupt its functionality. Users should update the router's software as soon as possible to fix this issue.
Original title
A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os...
Original description
A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used.
nvd CVSS2.0
7.5
nvd CVSS3.1
7.3
nvd CVSS4.0
6.9
Vulnerability type
CWE-77
Command Injection
CWE-78
OS Command Injection
Published: 7 Apr 2026 · Updated: 7 Apr 2026 · First seen: 7 Apr 2026