5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A weakness has been identified in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument langType causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Basic Information
ID
CVE-2026-7720
Source
VulDB
Published
May 4, 2026 at 01:45
Affected Product
Vendor
Totolink
Product
WA300
Version
5.2cu.7112_B20190227
Affected Versions
Totolink WA300 5.2cu.7112_B20190227