Critical Command Injection Flaws Expose Totolink A7100RU Routers to RCE
Two newly disclosed vulnerabilities, CVE-2026-5854 and CVE-2026-5977, affect the Totolink A7100RU router running firmware 7.4cu.2313_b20191024 and allow remote command execution without authentication or user interaction. Both flaws are in the router’s CGI handler at /cgi-bin/cstecgi.cgi: CVE-2026-5854 is tied to the setWiFiEasyCfg function through the merge argument, while CVE-2026-5977 affects setWiFiBasicCfg through the wifiOff argument.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Third Totolink A7100RU command injection flaw is disclosed as CVE-2026-5993
On 2026-04-10, CVE-2026-5993 was received for Totolink A7100RU firmware 7.4cu.2313_b20191024. The flaw affects the setWiFiGuestCfg function in /cgi-bin/cstecgi.cgi and allows remote OS command injection via the wifiOff argument without privileges or user interaction; public exploit information was noted.
Two command injection flaws in Totolink A7100RU are disclosed as CVEs
On April 9, 2026, CVE-2026-5854 and CVE-2026-5977 were recorded for Totolink A7100RU firmware 7.4cu.2313_b20191024. The flaws affect the setWiFiEasyCfg and setWiFiBasicCfg functions in /cgi-bin/cstecgi.cgi and allow remote OS command injection without privileges or user interaction; public exploit information was noted.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
CVE-2026-5993 - Totolink A7100RU CGI cstecgi.cgi setWiFiGuestCfg os command injection
cvefeed.io
Open sourceCVE-2026-5854 - Totolink A7100RU CGI cstecgi.cgi setWiFiEasyCfg os command injection
cvefeed.io
Open sourceCVE-2026-5977 - Totolink A7100RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
cvefeed.io
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


