CVE-2026-5978Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument mode leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-09: 3PoC Mentioned / Linked · 2026-04-09: 1Technical Details · 2026-04-09: 304-09
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-5978: CRITICAL] Critical security alert: Totolink A7100RU 7.4cu.2313_b20191024 has a vulnerability in setWiFiAclRules function allowing remote os command injection. Public exploit available.#cve,CVE-2026-5978,#cybersecurity https://cvefind.com/CVE-2026-5978

    Post summary

    The post announces a critical vulnerability in the Totolink A7100RU router, highlights a publicly available exploit, but does not detail the exploit code or report active exploitation.

    0000037
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5978 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the co… https://www.cve.org/CVERecord?id=CVE-2026-5978 ----- Traducción: CVE-2026-5978 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability affecting the Totolink A7100RU router's setWiFiAclRules function has been identified and recorded as CVE-2026-5978.

    0000025
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5978 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the co… https://www.cve.org/CVERecord?id=CVE-2026-5978

    Post summary

    The post reports the detection of CVE-2026-5978 in Totolink A7100RU firmware, detailing the affected function setWiFiAclRules in cstecgi.cgi, but offers no PoC, exploit details, or patch information.

    00000138
    57.0K followersView on X

Explore more