CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-5020 — A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected...

Sunday, March 29, 2026 at 01:15 AM UTC·Source: NIST NVD

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is now public and may be used.

Analysis

A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is now public and may be used. CVSS Score: 6.3. Published: 2026-03-29T01:15:57.133.

Indicators of Compromise (1)

CVE (1)
CVE-2026-5020
Source Attribution

Originally published by NIST NVD on Mar 29, 2026. Verified by: NIST.

Related Threats