---
id: CVE-2026-5678
title: A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024
summary: >-
  A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The
  affected element is the function setScheduleCfg of the file
  /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead
  to os command injection…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
published: '2026-04-06'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5678'
references:
  - url: >-
      https://github.com/Litengzheng/vuldb_new/blob/main/A7100RU/vul_185/README.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/792608'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/355505'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/355505/cti'
    label: cna@vuldb.com
  - url: 'https://www.totolink.net/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.0206
epssPercentile: 0.80493
ingestedAt: '2026-07-24T09:23:52.287Z'
---

## Overview

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
