CVE-2026-5996 is a critical operating system command injection vulnerability in the Totolik A7100RU router (firmware version 7.4cu.2313_b20191024) affecting the setAdvancedInfoShow function within the /cgi-bin/cstecgi.cgi CGI handler component. An attacker can manipulate the tty_server parameter to execute arbitrary OS commands on the affected device. The vulnerability carries a CVSS 3.1 score of 9.8 CRITICAL with a network-based attack vector requiring no authentication, low complexity, and no user interaction. Successful exploitation grants an attacker complete system compromise with high impact to confidentiality, integrity, and availability. While the vulnerability has been publicly disclosed, it is not currently listed on CISA's Known Exploited Vulnerabilities catalog, and there is no evidence of active exploitation in the wild. However, with a public disclosure and CVSS score in the critical range, defensive measures should be prioritized immediately. The relatively low EPSS score suggests community exploitation remains limited at present, though this does not diminish the urgency of mitigation efforts given the severity of potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Totolink | A7100RU | 7.4cu.2313_b20191024CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.