


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation…
Published:
6 april 2026 om 22:00:00
Alert date:
7 april 2026 om 01:00:39
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A remote command injection vulnerability (CVE-2026-5692) was discovered in Totolink A7100RU router firmware version 7.4cu.2313_b20191024. The vulnerability exists in the setGameSpeedCfg function within the /cgi-bin/cstecgi.cgi file, where manipulation of the 'enable' argument leads to OS command injection. The attack can be performed remotely, and a public exploit is available, making this a high-risk vulnerability for affected devices.
Technical details
Mitigation steps:
Affected products:
Totolink A7100RU
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5692
https://github.com/Litengzheng/vuldb_new/blob/main/A7100RU/vul_190/README.md
https://vuldb.com/submit/792963
https://vuldb.com/vuln/355519
https://vuldb.com/vuln/355519/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
