CVE-2026-5997General

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-10); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1Technical Details · 2026-04-10: 4Technical Details · 2026-04-11: 104-1004-11
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Exploit
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-104
Disclosure1Exploit1General2
2026-04-111
General1
Full discourse5 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-40089 | CVSS 9.9 🔴 CVE-2026-5997 | CVSS 9.8 🔴 CVE-2026-5996 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post simply enumerates three high‑severity CVEs with their CVSS scores and links to a vulnerability page, without providing any exploitation, patch, or deeper technical information.

    0001062
    5.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5997 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5997 #CVE-2026-5997 #CVE #Critical #CyberSecurity #InfoSec https://t.co/vpoLcdV4ER

    Post summary

    The tweet announces CVE-2026-5997 with a high severity score but offers no further details, PoCs, or exploitation evidence.

    0000045
    123 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-5997: Totolink A7100RU CGI cstecgi.cgi ... Remote RCE via password change form - attacker injects commands through `admpass` parameter, no auth required, public ex... https://zerodaysignal.com/vulnerability/CVE-2026-5997 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The message announces a new remote RCE vulnerability in the Totolink A7100RU’s CGI handler, highlighting unauthenticated command injection through the admpass parameter.

    0000053
    204 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5997 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the … https://www.cve.org/CVERecord?id=CVE-2026-5997

    Post summary

    The text announces CVE-2026-5997 in Totolink A7100RU, naming the affected function, but provides no details on PoC, exploitation, or mitigation.

    00000128
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-5997: CRITICAL] A cyber security vulnerability found in Totolink A7100RU can lead to remote os command injection through CGI Handler. Public exploit available. #cybersecurity#cve,CVE-2026-5997,#cybersecurity https://cvefind.com/CVE-2026-5997

    Post summary

    The tweet announces a critical OS command‑injection vulnerability (CVE‑2026‑5997) in the Totolink A7100RU and notes that a public exploit is available, though no specific exploit details or patch are linked.

    0000079
    619 followersView on X

Explore more