CVE-2026-5995
Published: 10 April 2026
Summary
CVE-2026-5995 is a high-severity Command Injection (CWE-77) vulnerability in Totolink A7100RU (inferred from references). Its CVSS base score is 8.9 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 24.0% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 AC-3 (Access Enforcement) and SI-10 (Information Input Validation).
Deeper analysis
A weakness has been identified in the Totolink A7100RU firmware version 7.4cu.2313_b20191024. The issue resides in the setMiniuiHomeInfoShow function within the /cgi-bin/cstecgi.cgi file of the CGI Handler component. Manipulation of the lan_info argument permits OS command injection, corresponding to CWE-77 and CWE-78, and carries a CVSS 4.0 score of 8.9 reflecting network-accessible attack conditions without required credentials or user interaction.
The flaw can be exploited remotely by unauthenticated attackers who supply crafted input to trigger arbitrary operating system command execution on the device. A public exploit has been released, enabling straightforward reproduction of the attack against exposed units.
EPSS scores remain low and essentially flat at 0.0122 current with a peak of 0.0125, indicating limited observed exploitation interest to date. The vendor site and public disclosure repositories provide the primary references, though no specific mitigation steps or patch details are included in the available information.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-21272
Vulnerability details
A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument lan_info can lead to os command injection. The attack may be…
more
performed from remote. The exploit has been made available to the public and could be used for attacks.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
CVE-2026-5995 enables remote unauthenticated OS command injection via a public-facing router CGI handler, directly facilitating T1190 (Exploit Public-Facing Application) and T1059.004 (Unix Shell) execution.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly blocks OS command injection by validating and sanitizing the lan_info argument before it reaches the CGI handler.
Enforces access control on /cgi-bin/cstecgi.cgi so unauthenticated remote callers cannot invoke setMiniuiHomeInfoShow.
Boundary protection can restrict or filter traffic to the device's web interface, reducing exposure of the vulnerable CGI endpoint.