CVE-2026-5677 is a remote code execution vulnerability in Totolik A7100RU router firmware version 7.4cu.2313_b20191024, specifically affecting the CsteSystem function in the /cgi-bin/cstecgi.cgi endpoint. An attacker can inject arbitrary operating system commands by manipulating the resetFlags parameter without requiring authentication or user interaction. This vulnerability allows an unauthenticated remote attacker to execute arbitrary code on affected routers. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector, low complexity, and no privilege or user interaction requirements. The attack impacts the confidentiality, integrity, and availability of the affected system, making it a significant threat to router security. The EPSS score of 0.048 indicates it poses a higher risk than approximately 89.6 percent of known vulnerabilities. Exploit code has been publicly released and is available for malicious use, though the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog. The CVE remains on an inactive status in threat tracking systems, suggesting limited active exploitation despite public exploit availability. Organizations operating Totolik A7100RU routers should prioritize patching or implementing network-level controls to restrict access to the vulnerable endpoint.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Totolink | A7100RU | 7.4cu.2313_b20191024CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.