CVE-2026-5030
MEDIUMA vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Published: 3/29/2026Modified: 3/30/2026
References (5)
https://lavender-bicycle-a5a.notion.site/TOTOLINK-NR1800X-NTPSyncWithHost-32153a41781f8032afebc0802b704e9c?source=copy_linkExploitThird Party Advisoryhttps://vuldb.com/submit/778529Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/353952Third Party AdvisoryVDB Entryhttps://vuldb.com/vuln/353952/ctiPermissions RequiredVDB Entryhttps://www.totolink.net/Product