CVE-2026-5851Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 7 mentions (2026-04-09); latest day: 1
  • 8 total mentions across 2 days

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-04-09: 7Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-09: 2Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 6Technical Details · 2026-04-10: 104-0904-10
Signal classification4 categories
Disclosure
562.5%
Exploit
112.5%
General
112.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-097
Disclosure4Exploit1General1Patch1
2026-04-101
Disclosure1
Full discourse8 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5851 — CVSS 9.8/10 ██████████ A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/6asjfIPIrt

    Post summary

    The tweet announces a critical vulnerability (CVE-2026-5851) in the Totolink A7100RU router and informs users that a patch is available.

    1000040
    16 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5851 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI… https://www.cve.org/CVERecord?id=CVE-2026-5851

    Post summary

    The post announces CVE‑2026‑5851 affecting Totolink A7100RU routers, detailing the affected component but providing no exploit, patch, or evidence of active exploitation.

    00010158
    57.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5851 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5851 #CVE-2026-5851 #CVE #Critical #CyberSecurity #InfoSec https://t.co/rxJBC4xCGO

    Post summary

    The tweet announces CVE‑2026‑5851 as a newly disclosed vulnerability with a high severity score of 9.8, without providing further technical or exploit details.

    0000036
    123 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-5851: Totolink A7100RU CGI cstecgi.cgi ... Totolink A7100RU's setUPnPCfg function blindly trusts user input in the 'enable' parameter - classic command injection w... https://zerodaysignal.com/vulnerability/CVE-2026-5851 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-5851, a command injection flaw in Totolink A7100RU routers, and links to an external site for further details, but provides no evidence of active exploitation or a patch.

    0000046
    204 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5851 OS Command Injection in Totolink A7100RU 7.4cu.2313_b20191024 via setUPnPCfg https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5851

    Post summary

    The post announces CVE-2026-5851 as an OS command injection flaw in Totolink A7100RU firmware, providing technical details but no PoC, exploit code, patch, or active exploitation evidence.

    0000035
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5851 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI… https://www.cve.org/CVERecord?id=CVE-2026-5851 ----- Traducción: CVE-2026-5851 Se … http://infoflow.cloud`

    Post summary

    The tweet merely announces the discovery of CVE‑2026‑5851 for a specific router model, referencing the CVE record, without providing technical details, PoC, or patch information.

    0000035
    67 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5851 - Totolink A7100RU CGI cstecgi.cgi setUPnPCfg os command injection Intel Report: https://ift.tt/E3pj4a6

    Post summary

    The notice identifies CVE-2026-5851 as an OS command injection flaw in the Totolink A7100RU, pointing to an Intel intel report for further details but providing no PoC, exploit code, or evidence of active exploitation.

    0000039
    280 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-5851: CRITICAL] Security flaw found in Totolink A7100RU 7.4cu.2313_b20191024! Vulnerability in setUPnPCfg of /cgi-bin/cstecgi.cgi allows remote OS command injection. Exploit available.#cve,CVE-2026-5851,#cybersecurity https://cvefind.com/CVE-2026-5851

    Post summary

    The post announces a remote OS command injection flaw in Totolink A7100RU and notes that an exploit is available, but does not provide code or evidence of in-the-wild use.

    0000055
    619 followersView on X

Explore more