CVE-2026-5977Disclosure

MEDIUMCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wifiOff can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-19: 1Exploit Tool / Code · 2026-04-19: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 1Technical Details · 2026-04-19: 104-0904-1004-19
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
Exploit
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure3
2026-04-101
Patch1
2026-04-191
Exploit1
Full discourse5 posts
  • Giuseppe Paternicola@giuseppe_1337
    Exploit

    🚨 CRITICAL: CVE-2026-5977 (CVSS 9.8) Totolink A7100RU router vulnerable to unauthenticated remote OS command injection via setWiFiBasicCfg function. Public exploit available. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/BXWlNQMuIE

    Post summary

    CVE-2026-5977 is a critical OS command injection flaw in Totolink A7100RU routers, a public exploit exists, and immediate patching is urged.

    01000150
    26 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5977 — CVSS 9.8/10 ██████████ A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/yWZlVNQnU9

    Post summary

    A critical vulnerability (CVE-2026-5977) in Totolink A7100RU has been disclosed, and a patch is immediately available.

    1000067
    16 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5977: CRITICAL] Weakness in Totolink A7100RU 7.4cu.2313_b20191024 allows remote attackers to launch OS command injections via a specific argument. Exploit now public.#cve,CVE-2026-5977,#cybersecurity https://cvefind.com/CVE-2026-5977

    Post summary

    CVE-2026-5977 is a critical command‑injection flaw in Totolink A7100RU that lets attackers spawn arbitrary OS commands. The vulnerability is announced and an exploit is declared public, but no specific exploit code, patch, or evidence of active exploitation is detailed.

    0000046
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5977 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI… https://www.cve.org/CVERecord?id=CVE-2026-5977 ----- Traducción: CVE-2026-5977 Se … http://infoflow.cloud`

    Post summary

    The post announces a newly identified weakness in a specific router model, providing limited technical detail but no evidence of exploitation or remediation.

    0000053
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5977 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI… https://www.cve.org/CVERecord?id=CVE-2026-5977

    Post summary

    The post discloses a new weakness in Totolink A7100RU firmware that affects WiFi configuration, but does not provide a PoC, exploit, or mitigation information.

    00000147
    57.0K followersView on X

Explore more