CVE-2026-5975Patch

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wanIdx leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-19: 104-0904-1004-19
Signal classification4 categories
Patch
240.0%
Disclosure
120.0%
General
120.0%
PoC
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure1General1PoC1
2026-04-101
Patch1
2026-04-191
Patch1
Full discourse5 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5975 — CVSS 9.8/10 ██████████ A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/vOUaBOqyLq

    Post summary

    CVE‑2026‑5975, a critical vulnerability in Totolink A7100RU firmware, has been disclosed with a patch already available.

    1000049
    16 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-5975 (CVSS 9.8) - OS Command Injection in Totolink A7100RU router. Exploit publicly available. Patch immediately or isolate affected devices. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/wko1Ht0ghQ

    Post summary

    The tweet reports a critical OS command injection CVE-2026-5975 affecting Totolink A7100RU routers, highlights a publicly available exploit, and urges immediate patching or isolation.

    0000070
    26 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5975: CRITICAL] Vulnerability in Totolink A7100RU 7.4cu.2313_b20191024 identified. Exploit allows remote OS command injection via setDmzCfg function in /cgi-bin/cstecgi.cgi component CGI Handler.#cve,CVE-2026-5975,#cybersecurity https://cvefind.com/CVE-2026-5975

    Post summary

    The text announces a critical CVE-2026-5975 affecting Totolink A7100RU routers, describing a remote OS command injection flaw in a CGI handler, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000030
    619 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5975 A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the componen… https://www.cve.org/CVERecord?id=CVE-2026-5975

    Post summary

    The post notes a new vulnerability in a Totolink router affecting a specific CGI function and links to a CVE record, but provides no deeper technical, exploit, or mitigation details.

    00000126
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-5975: Totolink A7100RU CGI cstecgi.cgi ... Remote RCE via DMZ config on ancient Totolink firmware - wanIdx parameter gets shell exec without auth, public exploit d... https://zerodaysignal.com/vulnerability/CVE-2026-5975 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a new CVE-2026-5975 that allows remote RCE on legacy Totolink firmware and cites a publicly available exploit, but provides no evidence of active exploitation or a patch.

    0000056
    204 followersView on X

Explore more