CVE-2026-5976Exploit

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sambaEnabled results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Exploit: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-13: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-13: 104-0904-13
Signal classification2 categories
Exploit
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure1Exploit1
2026-04-131
Exploit1
Full discourse3 posts
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-5976: Totolink A7100RU CGI cstecgi.cgi ... Unauthenticated RCE via `sambaEnabled` param manipulation in setStorageCfg - public exploit available for this ancient T... https://zerodaysignal.com/vulnerability/CVE-2026-5976 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces that CVE‑2026‑5976 allows unauthenticated remote code execution on a Totolink router via a CGI parameter; a public exploit exists and is referenced via a link.

    0000062
    218 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-5976: CRITICAL] Security flaw in Totolink A7100RU 7.4cu.2313_b20191024 allows remote attacks via CGI Handler component. Exploit for os command injection vulnerability is now public.#cve,CVE-2026-5976,#cybersecurity https://cvefind.com/CVE-2026-5976

    Post summary

    The message announces that a public exploit exists for a critical OS command injection flaw in the Totolink A7100RU, without providing the code itself or evidence of active attacks, and offers no patch information.

    0000049
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5976 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component … https://www.cve.org/CVERecord?id=CVE-2026-5976

    Post summary

    The article announces CVE-2026-5976 in a Totolink router, detailing the affected function but without any PoC, exploit, or patch information.

    0000097
    57.0K followersView on X

Explore more