These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-7218 is a buffer overflow vulnerability in Totolink N300RT 3.4.0-B20250430, impacting the function is_cmd_string_valid of the file /boafrm/formWsc in the component libapmib.so. The vulnerability allows for remote exploitation through manipulation of the localPin argument. Network administrators and security teams should be aware of this vulnerability and take immediate action to mitigate the risk [truncated]
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Users should assess the vulnerability and apply patches [truncated]
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521, affecting the setUrlFilterRules function in the /cgi-bin/cstecgi.cgi file of the CGI Handler component. The manipulation of the 'enable' argument results in OS command injection, allowing for remote exploitation. This issue has a high impact due to its remote exploitability and potential for command injection.
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521, affecting the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi in the CGI Handler component. The manipulation of the argument wscDisabled leads to OS command injection, which can be initiated remotely. This vulnerability has been publicly disclosed and may be used by attackers. Users of affected products should apply patches [truncated]
CVE-2026-5692 is an os command injection vulnerability impacting Totolink A7100RU 7.4cu.2313_b20191024. The vulnerability affects the setGameSpeedCfg function in /cgi-bin/cstecgi.cgi, allowing remote attackers to inject os commands by manipulating the enable argument. The attack may be performed from remote. The exploit has been made public and could be used. Users and administrators should review the vul [truncated]
CVE-2026-5690 is a medium-severity vulnerability in Totolink A7100RU 7.4cu.2313_b20191024. The setRemoteCfg function in /cgi-bin/cstecgi.cgi is susceptible to os command injection via the enable argument. This issue can be exploited remotely. The CVE record was published on 2026-04-06T23:16:31.563Z and was last modified on 2026-07-24T09:10:00.153Z. Users should review the official CVE record and NVD entry [truncated]
CVE-2026-5688 is an os command injection vulnerability in Totolink A7100RU 7.4cu.2313_b20191024 in the setDdnsCfg function of /cgi-bin/cstecgi.cgi. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Users of affected products should prioritize patching or applying mitigations to prevent exploitation. This vulnerability has a CVSS score of 5.5 and is classified as [truncated]
A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. This vulnerability has a CVSS score of 2 and a severity of LOW. Users of affected products should assess their exposure and apply vendor remediation if available.
A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. Users should assess the vulnerability and apply pat [truncated]
A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The impacted component is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection. The attack may be initiated remotely. This issue allows for remote exploitation, potentially leading to unauthorized command execution.