PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5692 Totolink CVE debrief

CVE-2026-5692 is an os command injection vulnerability impacting Totolink A7100RU 7.4cu.2313_b20191024. The vulnerability affects the setGameSpeedCfg function in /cgi-bin/cstecgi.cgi, allowing remote attackers to inject os commands by manipulating the enable argument. The attack may be performed from remote. The exploit has been made public and could be used. Users and administrators should review the vulnerability details and take necessary actions to mitigate the risk.

Vendor
Totolink
Product
A7100RU
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-07
Original CVE updated
2026-07-24
Advisory published
2026-04-07
Advisory updated
2026-07-24

Who should care

Users and administrators of Totolink A7100RU 7.4cu.2313_b20191024 should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review the vulnerability details, assess their exposure, and apply patches or mitigations as needed.

Technical summary

The vulnerability is caused by improper sanitization of user input in the setGameSpeedCfg function of /cgi-bin/cstecgi.cgi. An attacker can inject os commands by manipulating the enable argument. The CVSS score is 5.5 and the severity is MEDIUM. The vulnerability has been made public, and defenders should verify the affected scope and severity. Users and administrators of Totolink A7100RU 7.4cu.2313_b20191024 should review the vulnerability details, assess their exposure, and apply patches or mitigations as needed. The attack may be performed from remote, and the exploit has been made public and could be used. Evidence limits suggest further verification is needed to confirm affected scope and severity.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability.

Recommended defensive actions

  • Apply the patch or update provided by the vendor.
  • Restrict access to the /cgi-bin/cstecgi.cgi file.
  • Monitor the system for suspicious activity.
  • Implement additional security measures such as input validation and sanitization.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-04-07T00:16:20.347Z and was last modified on 2026-07-24T09:10:00.153Z. The NVD entry is currently Deferred. The vulnerability has been made public and could be used. Evidence limits suggest further verification is needed to confirm affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T00:16:20.347Z and has not been modified since then. The NVD entry is currently Deferred.