References https://telecom.cnvd.org.cn/?hmsr=websiteindices.com&utm_source=websiteindices.com&utm_medium=referral&max=20&offset=1740 https://www.cnvd.org.cn/flaw/show/CNVD-2025-14785 https://www.cnvd.org.cn/flaw/show/CNVD-2025-14786 https://www.cnvd.org.cn/flaw/show/CNVD-2025-13901 https://www.cnvd.org.cn/flaw/show/CNVD-2025-15259 https://cve.circl.lu/vuln/cnvd-2025-15261 https://avd.aliyun.com/product?prod=a3600r_firmware https://github.com/zxsssd/TotoLink- https://vuldb.com/vuln/353905 https://www.cve.org/CVERecord?id=CVE-2026-5020 https://radar.offseq.com/threat/cve-2026-5020-command-injection-in-totolink-a3600r-b468734a https://www.cvedetails.com/cve/CVE-2026-5020/ https://github.com/Darry-lang1/vuln/blob/main/TOTOLINK/A3600R/1/readme.md https://dbugs.ptsecurity.com/vulnerability/PT-2026-28734 https://app.opencve.io/cve/CVE-2026-5020 https://www.nmmapper.com/nvd/cve/CVE-2026-5020/ https://advisories.checkpoint.com/defense/advisories/public/2024/cpai-2024-0624.html https://security.bnu.edu.cn/ldgg/127768.html https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign https://www.instagram.com/p/DWdOsagj-YC/
Related VulnerabilitiesTOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞PoCCVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information DisclosurePoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-42887: TOTOLINK EX1200T 4.1.2cu.5215 - Authentication BypassPoCCVE-2022-25082: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-30013: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-46574: TOTOLINK A3700R - Command InjectionPoCCVE-2024-24328: TotoLink Router setMacFilterRules - Command InjectionPoCCVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection