CVE-2026-5020

A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:a3600r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3600r:-:*:*:*:*:*:*:*

History

29 Apr 2026, 01:00

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad en Totolink A3600R 4.1.2cu.5182_B20201102. Afectada por este problema es la función setNoticeCfg del archivo /cgi-bin/cstecgi.cgi del componente Gestor de Parámetros. La manipulación del argumento NoticeUrl resulta en inyección de comandos. El ataque puede lanzarse remotamente. El exploit ya es público y puede utilizarse.

30 Mar 2026, 19:01

Type Values Removed Values Added
References () https://lavender-bicycle-a5a.notion.site/TOTOLINK_A3600R_setNoticeCfg-32253a41781f80c197eaf8e7558c5ed1?source=copy_link - () https://lavender-bicycle-a5a.notion.site/TOTOLINK_A3600R_setNoticeCfg-32253a41781f80c197eaf8e7558c5ed1?source=copy_link - Exploit, Third Party Advisory
References () https://vuldb.com/submit/779536 - () https://vuldb.com/submit/779536 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/353905 - () https://vuldb.com/vuln/353905 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/353905/cti - () https://vuldb.com/vuln/353905/cti - Permissions Required, VDB Entry
References () https://www.totolink.net/ - () https://www.totolink.net/ - Product
First Time Totolink
Totolink a3600r Firmware
Totolink a3600r
CPE cpe:2.3:o:totolink:a3600r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3600r:-:*:*:*:*:*:*:*

29 Mar 2026, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-29 01:15

Updated : 2026-04-29 01:00


NVD link : CVE-2026-5020

Mitre link : CVE-2026-5020

CVE.ORG link : CVE-2026-5020


JSON object : View

Products Affected

totolink

  • a3600r
  • a3600r_firmware
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')