UNKNOWNCVE-2026-5020
Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection
Platform
other
Component
totolink-a3600r-firmware
A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
How to fix
Actualice el firmware del router Totolink A3600R a una versión posterior a 4.1.2cu.5182_B20201102 para corregir la vulnerabilidad de inyección de comandos. Consulte el sitio web del proveedor para obtener la última versión del firmware e instrucciones de actualización.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free