CVE-2026-5020

A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:a3600r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3600r:-:*:*:*:*:*:*:*

History

30 Mar 2026, 19:01

Type Values Removed Values Added
References () https://lavender-bicycle-a5a.notion.site/TOTOLINK_A3600R_setNoticeCfg-32253a41781f80c197eaf8e7558c5ed1?source=copy_link - () https://lavender-bicycle-a5a.notion.site/TOTOLINK_A3600R_setNoticeCfg-32253a41781f80c197eaf8e7558c5ed1?source=copy_link - Exploit, Third Party Advisory
References () https://vuldb.com/submit/779536 - () https://vuldb.com/submit/779536 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/353905 - () https://vuldb.com/vuln/353905 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/353905/cti - () https://vuldb.com/vuln/353905/cti - Permissions Required, VDB Entry
References () https://www.totolink.net/ - () https://www.totolink.net/ - Product
First Time Totolink
Totolink a3600r
Totolink a3600r Firmware
CPE cpe:2.3:o:totolink:a3600r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3600r:-:*:*:*:*:*:*:*

Information

Published : 2026-03-29 01:15

Updated : 2026-03-30 19:01


NVD link : CVE-2026-5020

Mitre link : CVE-2026-5020

CVE.ORG link : CVE-2026-5020


JSON object : View

Products Affected

totolink

  • a3600r_firmware
  • a3600r
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')