CVE-2026-7719Disclosure

MEDIUMCVSS 8.9 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument http_host results in buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-05-15); latest day: 1
  • 11 total mentions across 6 days

Deep dive

Activity timeline11 mentions / 6d
01345Mentions · 2026-05-03: 1Mentions · 2026-05-04: 2Mentions · 2026-05-11: 1Mentions · 2026-05-15: 5Mentions · 2026-05-24: 1Mentions · 2026-06-02: 1PoC Mentioned / Linked · 2026-05-24: 1Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-06-02: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-15: 4Technical Details · 2026-05-24: 1Technical Details · 2026-06-02: 105-0305-0405-1105-1505-2406-02
Signal classification4 categories
Disclosure
763.6%
Active Exploitation
218.2%
General
19.1%
Exploit
19.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-031
Disclosure1
2026-05-042
Disclosure2
2026-05-111
Active Exploitation1
2026-05-155
Disclosure4General1
2026-05-241
Exploit1
2026-06-021
Active Exploitation1
Full discourse11 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Totolink WA300 (CVE-2026-7719) https://vuldb.com/vuln/360895/cti

    Post summary

    The CTI team reports widespread activity targeting Totolink WA300 (CVE-2026-7719), suggesting the vulnerability is being actively exploited.

    02010101
    2.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-7719 · 9.8 → 3.1 The WiFi Router That Became a Backdoor: Totolink WA300 CVSS 9.8 RCE Now in the Wild

    Post summary

    CVE‑2026‑7719, an RCE vulnerability in Totolink WA300 routers with a CVSS score of 9.8, is now being actively exploited in the wild.

    1000044
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-7719 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry reports a new critical CVE with its CVSS details but provides no additional context such as proof of concept, exploitation, or mitigation steps.

    1000044
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7719-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text directs to an advisory link but contains no explicit details about the vulnerability, PoC, exploitation status, or mitigation.

    0001026
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-7719 (CVSS 9.8) — multiple products. CVE: CVE-2026-7719 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    This statement discloses the existence of a critical vulnerability, CVE-2026-7719, with a CVSS score of 9.8 and detailed exploit characteristics, but provides no PoC, exploit code, or mitigation information.

    1000043
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7719 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A security flaw has been discovered in Totolink WA300 5.2cu.7112B20190227.

    Post summary

    A critical vulnerability (CVE-2026-7719) was discovered in the Totolink WA300 firmware, with a CVSS score of 9.8 and marked as a critical advisory.

    1000042
    215 followersView on X
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-7719 — CVSS 9.8/10 ██████████ A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/tZ5Vt6P4b5

    Post summary

    The tweet discloses the discovery of CVE‑2026‑7719 in Totolink WA300, noting a high CVSS score and critical severity, and informs readers that a patch is now available, without providing PoC or exploit details.

    1000049
    26 followersView on X
  • DFIR Lab@DFIR_Lab
    Exploit

    🚨 CRITICAL: CVE-2026-7719 (CVSS 9.8) - Buffer overflow in Totolink WA300 router allows remote code execution via /cgi-bin/cstecgi[.]cgi. Public exploit available. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/CGTZjTfoEV

    Post summary

    The tweet warns of a critical buffer overflow in Totolink WA300 routers, notes a publicly available exploit, and urges immediate patching.

    0000095
    30 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    A critical CVE-2026-7719 affecting Totolink WA300 routers allows remote buffer overflow attacks. Mohawk Valley SMBs should check for affected devices and apply patches or mitigations immediately to reduce risk. Stay vigilant. #cybersecurity

    Post summary

    A remote buffer overflow vulnerability (CVE-2026-7719) in Totolink WA300 routers has been disclosed; users are urged to apply patches or mitigations immediately.

    0000048
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7719 Buffer Overflow in Totolink WA300 5.2cu.7112_B20190227 POST Request Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7719

    Post summary

    The post announces a buffer overflow vulnerability (CVE-2026-7719) affecting Totolink WA300’s POST request handler, providing technical details but no exploit or patch information.

    0000055
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Totolink WA300 (CVE-2026-7719) https://vuldb.com/vuln/360895

    Post summary

    A new vulnerability (CVE-2026-7719) affecting Totolink WA300 has been reported with a link to a vulnerability database entry.

    0000065
    2.1K followersView on X

Explore more