Two critical vulnerabilities, CVE-2026-5851 and CVE-2026-5976, were disclosed in the Totolink A7100RU router running firmware 7.4cu.2313_b20191024, exposing the device to remote OS command injection without authentication or user interaction. Both flaws affect /cgi-bin/cstecgi.cgi in the router's CGI handler: CVE-2026-5851 is tied to the setUPnPCfg function through the enable argument, while CVE-2026-5976 affects the setStorageCfg function through the sambaEnabled argument.
The vulnerabilities were classified under CWE-78 and CWE-77 and were assigned high to critical severity across CVSS versions, reflecting potential compromise of confidentiality, integrity, and availability. Public exploit information has reportedly been released, including references to VulDB and a GitHub disclosure repository, increasing the likelihood of exploitation against exposed devices that have not been updated or otherwise mitigated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-13, CVE-2026-6155 was recorded for a remote OS command injection flaw in the Totolink A7100RU router affecting /cgi-bin/cstecgi.cgi's setWanCfg function via the pppoeServiceName argument. The CVE entry states that public exploit information is available and maps the issue to CWE-78 and CWE-77.
On April 9, 2026, CVE-2026-5975 was recorded for a remote OS command injection flaw in Totolink A7100RU firmware 7.4cu.2313_b20191024. The vulnerability affects the setDmzCfg function in /cgi-bin/cstecgi.cgi via the wanIdx argument, and the CVE entry states that public exploit information is available.
The CVE records state that public exploit or disclosure material had been released for both vulnerabilities, including references to VulDB and a GitHub repository. This indicates technical details and exploit information were publicly available by the time the CVEs were published.
On April 9, 2026, CVE-2026-5851 and CVE-2026-5976 were recorded for remote OS command injection flaws in the Totolink A7100RU router firmware 7.4cu.2313_b20191024. The issues affect the setUPnPCfg and setStorageCfg functions in /cgi-bin/cstecgi.cgi and are described as remotely exploitable without authentication or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.