CVE-2026-5854Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument merge results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 6 mentions (2026-04-09); latest day: 1
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-04-09: 6Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-09: 2Exploit Tool / Code · 2026-04-09: 1Technical Details · 2026-04-09: 5Technical Details · 2026-04-10: 104-0904-10
Signal classification4 categories
Disclosure
342.9%
General
228.6%
Exploit
114.3%
PoC
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-096
Disclosure3Exploit1General1PoC1
2026-04-101
General1
Full discourse7 posts
  • CVE@CVEnew
    General

    CVE-2026-5854 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the com… https://www.cve.org/CVERecord?id=CVE-2026-5854

    Post summary

    The snippet reports the discovery of CVE-2026-5854 in Totolink A7100RU, noting the affected function, but provides no deeper technical or remediation details.

    00010158
    57.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5854 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5854 #CVE-2026-5854 #CVE #Critical #CyberSecurity #InfoSec https://t.co/1gOOTUO52F

    Post summary

    The tweet announces a new CVE with severity details but offers no technical depth, PoC, exploit, or patch information.

    0000023
    123 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-5854: Totolink A7100RU CGI cstecgi.cgi ... Unauthenticated RCE via WiFi config parameter - another Totolink router begging for a botnet membership with public expl... https://zerodaysignal.com/vulnerability/CVE-2026-5854 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post reports an unauthenticated RCE in Totolink A7100RU, provides a public exploit link, but does not indicate active exploitation or patch availability.

    00000123
    204 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5854 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the com… https://www.cve.org/CVERecord?id=CVE-2026-5854 ----- Traducción: CVE-2026-5854 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-5854 is a newly detected vulnerability in the Totolink A7100RU firmware, targeting the setWiFiEasyCfg function; no PoC, exploit, patch, or active exploitation details are shared.

    0000032
    67 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5854 OS Command Injection in Totolink A7100RU 7.4cu.2313_b20191024 via CGI Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5854

    Post summary

    The post announces a new OS Command Injection vulnerability in a Totolink router, providing basic technical details but no evidence of exploitation or remediation.

    0000035
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5854 - Totolink A7100RU CGI cstecgi.cgi setWiFiEasyCfg os command injection Intel Report: https://ift.tt/fd0SKnj

    Post summary

    The alert announces an OS command injection vulnerability (CVE-2026-5854) in the Totolink A7100RU device’s CGI interface, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000032
    280 followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-5854: CRITICAL] Critical vulnerability in Totolink A7100RU detected - issue allows remote os command injection through cgi-bin/cstecgi.cgi function setWiFiEasyCfg. Exploit now public.#cve,CVE-2026-5854,#cybersecurity https://cvefind.com/CVE-2026-5854

    Post summary

    The post reports a critical OS command injection vulnerability in the Totolink A7100RU router and confirms that a public exploit (PoC) is available.

    0000056
    619 followersView on X

Explore more