Unauthenticated Command Injection Flaws Disclosed in Totolink A7100RU Router
Two critical vulnerabilities, CVE-2026-5851 and CVE-2026-5976, were disclosed in the Totolink A7100RU router running firmware 7.4cu.2313_b20191024, exposing the device to remote OS command injection without authentication or user interaction. Both flaws affect /cgi-bin/cstecgi.cgi in the router's CGI handler: CVE-2026-5851 is tied to the setUPnPCfg function through the enable argument, while CVE-2026-5976 affects the setStorageCfg function through the sambaEnabled argument.
The vulnerabilities were classified under CWE-78 and CWE-77 and were assigned high to critical severity across CVSS versions, reflecting potential compromise of confidentiality, integrity, and availability. Public exploit information has reportedly been released, including references to VulDB and a GitHub disclosure repository, increasing the likelihood of exploitation against exposed devices that have not been updated or otherwise mitigated.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Fourth Totolink A7100RU command injection CVE is recorded
On 2026-04-13, CVE-2026-6155 was recorded for a remote OS command injection flaw in the Totolink A7100RU router affecting /cgi-bin/cstecgi.cgi's setWanCfg function via the pppoeServiceName argument. The CVE entry states that public exploit information is available and maps the issue to CWE-78 and CWE-77.
Third Totolink A7100RU command injection CVE is recorded
On April 9, 2026, CVE-2026-5975 was recorded for a remote OS command injection flaw in Totolink A7100RU firmware 7.4cu.2313_b20191024. The vulnerability affects the setDmzCfg function in /cgi-bin/cstecgi.cgi via the wanIdx argument, and the CVE entry states that public exploit information is available.
Public exploit information is available for the Totolink flaws
The CVE records state that public exploit or disclosure material had been released for both vulnerabilities, including references to VulDB and a GitHub repository. This indicates technical details and exploit information were publicly available by the time the CVEs were published.
Two Totolink A7100RU command injection CVEs are recorded
On April 9, 2026, CVE-2026-5851 and CVE-2026-5976 were recorded for remote OS command injection flaws in the Totolink A7100RU router firmware 7.4cu.2313_b20191024. The issues affect the setUPnPCfg and setStorageCfg functions in /cgi-bin/cstecgi.cgi and are described as remotely exploitable without authentication or user interaction.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
CVE-2026-6155 - Totolink A7100RU CGI cstecgi.cgi setWanCfg os command injection
cvefeed.io
Open sourceCVE-2026-5851 - Totolink A7100RU CGI cstecgi.cgi setUPnPCfg os command injection
cvefeed.io
Open sourceCVE-2026-5975 - Totolink A7100RU CGI cstecgi.cgi setDmzCfg os command injection
cvefeed.io
Open sourceCVE-2026-5976 - Totolink A7100RU CGI cstecgi.cgi setStorageCfg os command injection
cvefeed.io
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


