CVE-2026-5996Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument tty_server leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-10); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 4Technical Details · 2026-04-14: 104-1004-1104-14
Signal classification4 categories
Disclosure
350.0%
General
116.7%
Patch
116.7%
Exploit
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-104
Disclosure2General1Patch1
2026-04-111
Disclosure1
2026-04-141
Exploit1
Full discourse6 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-40089 | CVSS 9.9 🔴 CVE-2026-5997 | CVSS 9.8 🔴 CVE-2026-5996 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three high‑CVSS CVEs and directs readers to a reference link, but offers no further exploitation details, patch info, or deep technical context.

    0001062
    5.6K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5996 — CVSS 9.8/10 ██████████ A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/mqCFOgRSvC

    Post summary

    The tweet announces a critical CVE-2026-5996 vulnerability in a Totolink router model and urges users to apply the available patch.

    1000030
    16 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-5996: Totolink A7100RU CGI cstecgi.cgi ... Remote RCE via tty_server param in cstecgi.cgi - another Totolink router with zero auth barriers and public exploits flo... https://zerodaysignal.com/vulnerability/CVE-2026-5996 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a Remote RCE vulnerability (CVE‑2026‑5996) in Totolink A7100RU routers, revealing that the cstecgi.cgi’s tty_server parameter can be abused without authentication and that public exploits exist. No mitigation, patch, or active exploitation evidence is provided.

    0000058
    218 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5996 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5996 #CVE-2026-5996 #CVE #Critical #CyberSecurity #InfoSec https://t.co/hXzh4V8l2R

    Post summary

    A tweet announces the newly disclosed CVE-2026-5996 with its severity score and links to the NVD page, but offers no additional technical, exploit, or patch information.

    0000035
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5996 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setAdvancedInfoShow of the file /cgi-bin/cstec… https://www.cve.org/CVERecord?id=CVE-2026-5996

    Post summary

    A new CVE (CVE-2026-5996) has been identified in a Totolink router model, pinpointing a vulnerable function in the firmware, but no PoC, exploit, or mitigation information is provided.

    00000147
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5996: CRITICAL] Security alert: Vulnerability found in Totolink A7100RU router's CGI Handler component allowing remote OS command injection through manipulation of the tty_server argument. Exploit pu...#cve,CVE-2026-5996,#cybersecurity https://cvefind.com/CVE-2026-5996

    Post summary

    The post announces a critical remote OS command injection vulnerability (CVE-2026-5996) in Totolink A7100RU routers, detailing the affected component and the exploit vector, with no information on exploits, patches, or active attacks.

    0000075
    619 followersView on X

Explore more