CVE-2026-5997
Published: 10 April 2026
Summary
CVE-2026-5997 is a high-severity Command Injection (CWE-77) vulnerability in Totolink A7100RU (inferred from references). Its CVSS base score is 8.9 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 24.3% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 AC-3 (Access Enforcement) and SI-10 (Information Input Validation).
Deeper analysis
A vulnerability identified as CVE-2026-5997 affects the Totolink A7100RU router running firmware version 7.4cu.2313_b20191024. It resides in the setLoginPasswordCfg function within the /cgi-bin/cstecgi.cgi file of the CGI Handler component. Manipulation of the admpass argument enables OS command injection, corresponding to CWE-77 and CWE-78, and the flaw can be triggered remotely without authentication.
An attacker with network access can supply crafted input to the affected CGI endpoint and execute arbitrary operating system commands on the device. Successful exploitation grants full control over confidentiality, integrity, and availability of the router, consistent with the CVSS 8.9 rating. The exploit code has been made public and is available for use.
The EPSS score remains low, moving only from 0.0122 to a peak of 0.0125 with no material increase after disclosure. Public references include a detailed proof-of-concept repository and entries on VulDB, while the vendor site provides no additional mitigation guidance in the supplied data.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-21276
Vulnerability details
A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass results in os command injection. It is possible to launch…
more
the attack remotely. The exploit is now public and may be used.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
The vulnerability is a remote unauthenticated OS command injection in a public-facing web CGI interface on a router, directly enabling T1190 (Exploit Public-Facing Application) and facilitating arbitrary command execution matching T1059.008 (Network Device CLI).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly requires validation and sanitization of the admpass argument supplied to setLoginPasswordCfg, blocking the OS command injection vector.
Enforces authentication and authorization checks before any CGI request reaches the vulnerable setLoginPasswordCfg function, eliminating the unauthenticated remote attack path.
Restricts network access to the router's management CGI endpoints, limiting the remote attack surface that enables exploitation of CVE-2026-5997.