Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilityproof-of-concept-releaserapid-weaponization

Unauthenticated Command Injection Flaws Disclosed in Totolink A7100RU Router

Updated 2mo agoFirst seen Apr 9, 20264 sources

Two critical vulnerabilities, CVE-2026-5851 and CVE-2026-5976, were disclosed in the Totolink A7100RU router running firmware 7.4cu.2313_b20191024, exposing the device to remote OS command injection without authentication or user interaction. Both flaws affect /cgi-bin/cstecgi.cgi in the router's CGI handler: CVE-2026-5851 is tied to the setUPnPCfg function through the enable argument, while CVE-2026-5976 affects the setStorageCfg function through the sambaEnabled argument.

The vulnerabilities were classified under CWE-78 and CWE-77 and were assigned high to critical severity across CVSS versions, reflecting potential compromise of confidentiality, integrity, and availability. Public exploit information has reportedly been released, including references to VulDB and a GitHub disclosure repository, increasing the likelihood of exploitation against exposed devices that have not been updated or otherwise mitigated.

Share:
Unauthenticated Command Injection Flaws Disclosed in Totolink A7100RU Router
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 13, 20262mo ago

Fourth Totolink A7100RU command injection CVE is recorded

On 2026-04-13, CVE-2026-6155 was recorded for a remote OS command injection flaw in the Totolink A7100RU router affecting /cgi-bin/cstecgi.cgi's setWanCfg function via the pppoeServiceName argument. The CVE entry states that public exploit information is available and maps the issue to CWE-78 and CWE-77.

CVE-2026-6155 - Totolink A7100RU CGI cstecgi.cgi setWanCfg os command injection
Apr 9, 20263mo ago

Third Totolink A7100RU command injection CVE is recorded

On April 9, 2026, CVE-2026-5975 was recorded for a remote OS command injection flaw in Totolink A7100RU firmware 7.4cu.2313_b20191024. The vulnerability affects the setDmzCfg function in /cgi-bin/cstecgi.cgi via the wanIdx argument, and the CVE entry states that public exploit information is available.

CVE-2026-5975 - Totolink A7100RU CGI cstecgi.cgi setDmzCfg os command injection

Public exploit information is available for the Totolink flaws

The CVE records state that public exploit or disclosure material had been released for both vulnerabilities, including references to VulDB and a GitHub repository. This indicates technical details and exploit information were publicly available by the time the CVEs were published.

Two Totolink A7100RU command injection CVEs are recorded

On April 9, 2026, CVE-2026-5851 and CVE-2026-5976 were recorded for remote OS command injection flaws in the Totolink A7100RU router firmware 7.4cu.2313_b20191024. The issues affect the setUPnPCfg and setStorageCfg functions in /cgi-bin/cstecgi.cgi and are described as remotely exploitable without authentication or user interaction.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.