CVE-2026-4497

A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-20 19:16

Updated : 2026-03-23 14:32


NVD link : CVE-2026-4497

Mitre link : CVE-2026-4497

CVE.ORG link : CVE-2026-4497


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')