CVE-2026-5852Disclosure

MEDIUMCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 7 mentions (2026-04-09); latest day: 1
  • 8 total mentions across 2 days

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-04-09: 7Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-09: 1Exploit Tool / Code · 2026-04-09: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 5Technical Details · 2026-04-10: 104-0904-10
Signal classification4 categories
Disclosure
450.0%
General
225.0%
Exploit
112.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-097
Disclosure3Exploit1General2Patch1
2026-04-101
Disclosure1
Full discourse8 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5852 — CVSS 9.8/10 ██████████ A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/kQRvtMZngB

    Post summary

    A critical vulnerability (CVE-2026-5852) was disclosed in Totolink A7100RU with a CVSS of 9.8, and a patch is now available.

    1000030
    16 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5852 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5852 #CVE-2026-5852 #CVE #Critical #CyberSecurity #InfoSec https://t.co/LVBtlmR3Pb

    Post summary

    The post highlights the new CVE‑2026‑5852 with a high severity score and links to the NVD entry, but it provides no additional technical specs, exploit code, or patch information.

    0000029
    123 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-5852: Totolink A7100RU CGI cstecgi.cgi ... Remote RCE via igmpVer parameter in setIptvCfg - public exploit available for this ancient Totolink router with zero aut... https://zerodaysignal.com/vulnerability/CVE-2026-5852 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A public exploit for CVE‑2026‑5852 on the Totolink A7100RU router demonstrates remote code execution via the igmpVer parameter; no evidence of active exploitation or patch recommendations is provided.

    0000062
    204 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5852 OS Command Injection in Totolink A7100RU 7.4cu.2313_b20191024 via igmpVer Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5852

    Post summary

    The post discloses an OS command injection vulnerability in a specific Totolink router model, detailing the affecting firmware and trigger parameter, but offers no PoC, exploit code, patch information, or evidence of active exploitation.

    0000040
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5852 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handl… https://www.cve.org/CVERecord?id=CVE-2026-5852 ----- Traducción: CVE-2026-5852 Se … http://infoflow.cloud`

    Post summary

    The post merely announces the identification of a weakness in a Totolink router, referencing the CVE record but providing no further detail such as PoC, exploit, or mitigation.

    0000032
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5852 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handl… https://www.cve.org/CVERecord?id=CVE-2026-5852

    Post summary

    The statement only identifies a weakness in a specific firmware version and function, offering no details on exploitation, patches, or technical characteristics.

    00000154
    57.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5852 - Totolink A7100RU CGI cstecgi.cgi setIptvCfg os command injection Intel Report: https://ift.tt/7QwL2X5

    Post summary

    The tweet announces a new OS command injection vulnerability (CVE-2026-5852) in the Totolink A7100RU router and links to an Intel report for more details.

    0000030
    280 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5852: CRITICAL] Critical vulnerability discovered in Totolink A7100RU 7.4cu.2313_b20191024. Exploit enables remote OS command injection through the CGI Handler component, posing a significant cyber s...#cve,CVE-2026-5852,#cybersecurity https://cvefind.com/CVE-2026-5852

    Post summary

    The notice announces a critical remote OS command injection vulnerability (CVE‑2026‑5852) affecting Totolink A7100RU routers, providing technical detail but no PoC, exploit code, or patch information, and no evidence of active exploitation.

    0000075
    619 followersView on X

Explore more