CVE-2026-5850Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Exploit: 1 classified signal
  • Peaked 2d ago at 6 mentions (2026-04-09); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-04-09: 6Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-13: 1Patch / Workaround · 2026-04-09: 2Technical Details · 2026-04-09: 4Technical Details · 2026-04-10: 1Technical Details · 2026-04-13: 104-0904-1004-13
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
Exploit
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-096
Disclosure4Patch2
2026-04-101
Disclosure1
2026-04-131
Exploit1
Full discourse8 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5850 A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI H… https://www.cve.org/CVERecord?id=CVE-2026-5850

    Post summary

    The post briefly announces the presence of CVE‑2026‑5850 in the Totolink A7100RU router, indicating the affected function and file but lacks further exploitation or remediation details.

    00010172
    57.0K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5850 — CVSS 9.8/10 ██████████ A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/65Js7MfpF2

    Post summary

    The tweet announces a critical vulnerability in a Totolink router and highlights that a patch is now available, with no evidence of active exploitation or proof‑of‑concept.

    1000042
    16 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-5850: Totolink A7100RU CGI cstecgi.cgi ... Another Totolink router with unauthenticated RCE via CGI parameter injection - public exploit available for this 9.3 CVS... https://zerodaysignal.com/vulnerability/CVE-2026-5850 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-5850, an unauthenticated remote code execution bug in Totolink routers, noting that a public exploit is available via the provided link.

    0000066
    218 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5850 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5850 #CVE-2026-5850 #CVE #Critical #CyberSecurity #InfoSec https://t.co/qgd3wfz9Yp

    Post summary

    A succinct alert announcing CVE-2026-5850 with a high severity rating, but no additional technical details, PoC, or mitigation information.

    0000026
    123 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5850 OS Command Injection in Totolink A7100RU 7.4cu.2313_b20191024 CGI Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5850

    Post summary

    CVE-2026-5850, an OS Command Injection flaw affecting Totolink A7100RU routers, has been disclosed, providing technical details but no evidence of exploitation or mitigation.

    0000033
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5850 A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI H… https://www.cve.org/CVERecord?id=CVE-2026-5850 ----- Traducción: CVE-2026-5850 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-5850 in Totolink A7100RU, noting it affects the setVpnPassCfg function, but it does not provide any PoC, exploit, active usage, patch, or detailed technical vulnerability data.

    0000035
    67 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5850 - Totolink A7100RU CGI cstecgi.cgi setVpnPassCfg os command injection Intel Report: https://ift.tt/RkVAy0g

    Post summary

    The post announces a new OS command injection vulnerability (CVE-2026-5850) affecting the Totolink A7100RU device, providing technical details but no PoC, exploit code, active exploitation, or patch information.

    0000041
    280 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-5850: CRITICAL] Critical vulnerability identified in Totolink A7100RU! Disable remote access & update firmware immediately to prevent potential cyber attacks. #CyberSecurity#cve,CVE-2026-5850,#cybersecurity https://cvefind.com/CVE-2026-5850

    Post summary

    The post focuses on urging users to disable remote access and update firmware, highlighting a patch/workaround, without providing PoC or exploitation details.

    0000060
    619 followersView on X

Explore more