← Back to browse · API

CVE-2026-5854

Severity
CRITICAL
CVSS
9.3
EPSS
0.17546
Risk score
43.34
CISA KEV
No
PoC
No
Published
2026-04-09
Modified
2026-04-09
First seen
2026-08-07
Aliases
EUVD-2026-20870
Products
Totolink:A7100RU 7.4cu.2313_b20191024
Sources
euvd EUVD-2026-20870

Description

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument merge results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

References