CVE-2026-5995 is an OS command injection vulnerability in Totolik A7100RU firmware version 7.4cu.2313_b20191024, specifically in the setMiniuiHomeInfoShow function of the CGI Handler component. The vulnerability allows remote attackers to execute arbitrary commands by manipulating the lan_info argument in the /cgi-bin/cstecgi.cgi endpoint. The vulnerability has a CVSS score of 9.8 (CRITICAL) with a network-based attack vector that requires no authentication or user interaction, making it highly exploitable. The attack has low complexity and can result in complete compromise of system confidentiality, integrity, and availability. Exploit code has been publicly disclosed and is available for potential attackers to use. However, the vulnerability is not currently tracked on the CISA Known Exploited Vulnerabilities (KEV) list, and community attention appears limited with an EPSS score of 0.0125, indicating relatively low prevalence in active exploitation compared to other CVEs. Organizations running the affected Totolik device should apply patches immediately given the critical severity and public availability of exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Totolink | A7100RU | 7.4cu.2313_b20191024CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.