References https://www.cve.org/CVERecord?id=CVE-2026-5030 https://nvd.nist.gov/vuln/detail/CVE-2026-7721 https://app.opencve.io/cve/CVE-2026-9513 https://github.com/Double-q1015/CVE-vulns/blob/main/totolink_ca300-poe/NTPSyncWithHost/NTPSyncWithHost.md https://www.cvedetails.com/cve/CVE-2026-5030/ https://access.redhat.com/security/cve/cve-2025-55901 https://www.codeant.ai/vulnerability-database/cve-2025-70328 https://cert.kenet.or.ke/cve-2026-7721-totolink-wa300-cstecgicgi-ntpsyncwithhost-command-injection https://vuldb.com/vuln/272786
Related VulnerabilitiesTOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞PoCCVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information DisclosurePoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-42887: TOTOLINK EX1200T 4.1.2cu.5215 - Authentication BypassPoCCVE-2022-25082: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-30013: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-46574: TOTOLINK A3700R - Command InjectionPoCCVE-2024-24328: TotoLink Router setMacFilterRules - Command InjectionPoCCVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection