CVE-2026-5692 is an operating system command injection vulnerability discovered in the Totolik A7100RU router running firmware version 7.4cu.2313_b20191024. The flaw exists in the setGameSpeedCfg function within the /cgi-bin/cstecgi.cgi file, where improper sanitization of the "enable" parameter allows attackers to inject arbitrary commands. This vulnerability affects a network-accessible component with no authentication requirements. The vulnerability carries a CVSS 3.1 severity rating of 7.3 (HIGH), indicating significant risk. The attack vector is network-based with low complexity, requiring no user interaction or privileges, which substantially lowers the barrier to exploitation. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary commands with router-level privileges, potentially compromising network security, device integrity, and availability. Exploit code for this vulnerability has been made publicly available, though it is not currently listed in the CISA Known Exploited Vulnerabilities catalog and shows low exploitation prevalence based on its EPSS score of 0.012. The vulnerability is not actively trending, suggesting limited community attention at present. Organizations operating affected Totolink router models should prioritize firmware updates and implement network segmentation to mitigate this publicly disclosed threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Totolink | A7100RU | 7.4cu.2313_b20191024CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.