CVE-2026-5678Disclosure

LOWCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-06); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-04-06: 2Mentions · 2026-04-07: 1Active Exploitation · 2026-03-15: 1Technical Details · 2026-04-06: 2Technical Details · 2026-04-07: 103-1403-1504-0604-07
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-141
General1
2026-03-151
Active Exploitation1
2026-04-062
Disclosure2
2026-04-071
Disclosure1
Full discourse5 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5678 - Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection Intel Report: https://ift.tt/4mVXP5g

    Post summary

    This alert announces CVE-2026-5678, a command‑injection vulnerability in Totolink A7100RU, but does not provide PoC, exploit, or patch details.

    0000036
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5678 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing… https://www.cve.org/CVERecord?id=CVE-2026-5678 ----- Traducción: CVE-2026-5678 Se … http://infoflow.cloud`

    Post summary

    A new CVE, CVE‑2026‑5678, affecting Totolink A7100RU routers via the setScheduleCfg function in /cgi-bin/cstecgi.cgi has been identified. No PoC, exploitation activity, or patch information is provided.

    0000037
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5678 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing… https://www.cve.org/CVERecord?id=CVE-2026-5678

    Post summary

    CVE-2026-5678, a weakness in Totolink A7100RU's setScheduleCfg function, has been identified; the post provides technical details but no PoC, exploit, or patch information.

    00000192
    57.0K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Massive ransomware attack hits US healthcare providers, exploiting EHR zero-day CVE-2026-5678 to encrypt 500k+ patient records and demand $10M. Hospitals race to restore systems. #Ransomware https://threatcluster.io/cluster/massive-ransomware-attack-hits-healthcare-sector-demands-10m-01e3baef

    Post summary

    The post reports a large ransomware attack on US healthcare providers exploiting a zero-day CVE-2026-5678, demonstrating active exploitation of patient data with a $10M ransom demand.

    0000076
    101 followersView on X
  • Xghost@skyeye001
    General

    π Day 2026 特别之处:3.14 1:59:26 今天不只是数学家的节日。在安全领域,π 提醒我们一个残酷真理——有些东西永远算不完、永远有下一位。 就像漏洞。你修了 CVE-2026-1234,明天就来 CVE-2026-5678。无限循环小数,无限循环的补丁。 但这也是为什么这行有意思——永远有新问题等着你解。 Happy Pi Day! 🥧

    Post summary

    The post muses that new CVEs continually emerge, citing CVE‑2026‑1234 and CVE‑2026‑5678, but offers no technical, exploit, or patch information.

    0000051
    92 followersView on X

Explore more