← Back to browse · API

CVE-2026-5850

Severity
CRITICAL
CVSS
9.3
EPSS
0.15952
Risk score
42.78
CISA KEV
No
PoC
No
Published
2026-04-09
Modified
2026-04-13
First seen
2026-08-07
Aliases
EUVD-2026-20862, GHSA-2VW5-MF9H-8P68
Products
Totolink:A7100RU 7.4cu.2313_b20191024
Sources
euvd EUVD-2026-20862

Description

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

References