CVE-2026-5853Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument addrPrefixLen leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 6 mentions (2026-04-09); latest day: 1
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-04-09: 6Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-09: 1Exploit Tool / Code · 2026-04-09: 1Technical Details · 2026-04-09: 6Technical Details · 2026-04-10: 104-0904-10
Signal classification2 categories
Disclosure
685.7%
Exploit
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-096
Disclosure5Exploit1
2026-04-101
Disclosure1
Full discourse7 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5853 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5853 #CVE-2026-5853 #CVE #Critical #CyberSecurity #InfoSec https://t.co/MuZL9sSCwD

    Post summary

    A new CVE-2026-5853 has been announced with a severity score of 9.8, but no further technical details, patch information, or exploitation evidence are provided.

    0000027
    123 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-5853: Totolink A7100RU CGI cstecgi.cgi ... Remote RCE via IPv6 parameter injection in consumer routers - public exploit available, zero auth required, perfect for ... https://zerodaysignal.com/vulnerability/CVE-2026-5853 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑5853, highlighting a publicly available remote RCE exploit for Totolink A7100RU routers that requires no authentication, but it does not mention active exploitation evidence or a patch.

    0000067
    204 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5853 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/c… https://www.cve.org/CVERecord?id=CVE-2026-5853 ----- Traducción: CVE-2026-5853 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑5853 in the Totolink A7100RU device, noting the vulnerable "setIpv6LanCfg" function, but provides no evidence of exploitation, PoC, patch, or false‑positive claim.

    0000032
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5853 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/c… https://www.cve.org/CVERecord?id=CVE-2026-5853

    Post summary

    CVE-2026-5853 has been reported as affecting the setIpv6LanCfg function in /cgi-bin/c of a Totolink router, with no PoC, exploit, patch, or evidence of active exploitation provided.

    00000162
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5853 OS Command Injection in Totolink A7100RU 7.4cu.2313_b20191024 via setIpv6LanCfg https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5853

    Post summary

    The post announces an OS command injection vulnerability (CVE‑2026‑5853) in the Totolink A7100RU router's setIpv6LanCfg interface, providing technical detail but no PoC, exploit, or mitigation information.

    0000031
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5853 - Totolink A7100RU CGI cstecgi.cgi setIpv6LanCfg os command injection Intel Report: https://ift.tt/2ZP3ktG

    Post summary

    The alert announces the discovery of CVE-2026-5853, detailing an OS command‑injection vulnerability in Totolink routers, but does not provide proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    0000029
    280 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5853: CRITICAL] Security alert: Vulnerability found in Totolink A7100RU 7.4cu.2313_b20191024. Remote os command injection possible through setIpv6LanCfg function. Immediate action needed.#cve,CVE-2026-5853,#cybersecurity https://cvefind.com/CVE-2026-5853

    Post summary

    The post announces a critical OS command injection vulnerability in Totolink A7100RU routers via the `setIpv6LanCfg` function; no exploit tool, PoC, patch, or active exploitation evidence is provided.

    0000076
    619 followersView on X

Explore more