CVE-2026-5993Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wifiOff leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-10); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-10: 2Mentions · 2026-04-11: 1Technical Details · 2026-04-10: 204-1004-11
Signal classification3 categories
Disclosure
133.3%
Exploit
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-102
Disclosure1Exploit1
2026-04-111
General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5993 A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi of the… https://www.cve.org/CVERecord?id=CVE-2026-5993

    Post summary

    A new vulnerability in the TOTOLINK A7100RU router firmware was disclosed, affecting the setWiFiGuestCfg function in cstecgi.cgi; no PoC, exploit, or patch information is provided.

    00011129
    57.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5993 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5993 #CVE-2026-5993 #CVE #Critical #CyberSecurity #InfoSec https://t.co/PhH9UU2fxa

    Post summary

    The tweet merely states the existence of a new critical CVE with a reference to the NVD page, lacking additional technical or exploit information.

    0000040
    123 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-5993: CRITICAL] Critical vulnerability found in Totolink A7100RU 7.4cu.2313_b20191024 allows remote code execution with os command injection. Attack exploit is public and dangerous.#cve,CVE-2026-5993,#cybersecurity https://cvefind.com/CVE-2026-5993

    Post summary

    The post announces a critical CVE with remote code execution via command injection and states that a public exploit exists, though it provides no evidence of actual exploitation or a patch.

    0000053
    619 followersView on X

Explore more