CVE-2026-5020Disclosure(totolink / a3600r)

LOWCVSS 9.8 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch totolink a3600r systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is now public and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • a3600r
  • a3600r_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
a3600ra3600r_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-29: 5Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-29: 403-29
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5020 A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the comp… https://www.cve.org/CVERecord?id=CVE-2026-5020

    Post summary

    The message announces the detection of CVE-2026-5020 in Totolink A3600R firmware, noting that it affects the setNoticeCfg function in /cgi-bin/cstecgi.cgi, but provides no proof‑of‑concept, exploit, or patch information.

    0001059
    56.9K followersView on X
  • NerdieNews@NewsNerdie
    Patch

    Remote attackers can exploit CVE-2026-5020 in Totolink A3600R to execute arbitrary commands via the setNoticeCfg. This vulnerability could lead to complete system compromise. Update firmware immediately to mitigate risks. #CyberSecurity #InfoSec https://t.co/5i8oMRpU7P

    Post summary

    The post warns that CVE-2026-5020 allows remote command execution on Totolink A3600R and recommends updating firmware immediately to mitigate the risk.

    0000039
    53 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5020 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5020 #CVE-2026-5020 #CVE #Medium #CyberSecurity #InfoSec https://t.co/X45K6QyFa4

    Post summary

    The tweet simply announces CVE-2026‑5020 with a medium severity rating but provides no actionable or technical information.

    0000034
    123 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    TOTOLINK A3600R Command Injection Vulnerability CVE-2026-5020 Exposed: Public Exploit Risks Router Takeover https://cybersecuritypath.com/totolink-a3600r-command-injection-vulnerability-cve-2026-5020-exposed-public-exploit-risks-router-takeover/ #cybersecuritynews #TOTOLINK

    Post summary

    The post announces a new command injection vulnerability (CVE-2026-5020) in TOTOLINK A3600R routers, indicating potential exploitation risk but providing no PoC, exploit code, or patch information.

    0000034
    3 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5020 - Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection Intel Report: https://ift.tt/4uTLsHD

    Post summary

    The alert announces a new command‑injection vulnerability (CVE-2026-5020) affecting the Totolink A3600R via the cstecgi.cgi setNoticeCfg parameter, but provides no PoC, exploit, or mitigation details.

    0000020
    280 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtotolinka3600r---
OStotolinka3600r_firmware4.1.2cu.5182_b20201102--

Explore more