<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-91853 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-91853/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 17:46:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-91853/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in TOTOLINK X5000R</title><link>https://feed.craftedsignal.io/briefs/2026-09-totolink-rce/</link><pubDate>Tue, 15 Sep 2026 17:46:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-totolink-rce/</guid><description>A remote OS command injection vulnerability in the TOTOLINK X5000R router allows unauthenticated attackers to execute arbitrary commands via the exportOvpn function.</description><content:encoded><![CDATA[<p>The TOTOLINK X5000R router, specifically version 9.1.0cu.2089_B20211224, is susceptible to an OS command injection vulnerability (CVE-2026-91853). The vulnerability resides within the exportOvpn handler, which is invoked via the /cgi-bin/cstecgi.cgi script. An attacker can trigger this flaw by manipulating the filetype argument during an export request. Because the application fails to properly sanitize user-supplied input before passing it to the underlying system shell, an unauthenticated remote attacker can achieve arbitrary code execution. This vulnerability is publicly disclosed, increasing the risk of exploitation by opportunistic actors targeting edge network infrastructure. Defenders should monitor web server logs for suspicious requests directed at the exportOvpn handler.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to execute arbitrary operating system commands on the affected router. This could result in full device compromise, unauthorized access to internal network traffic, and the use of the router as a pivot point for further lateral movement within the environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web server traffic for HTTP requests targeting /cgi-bin/cstecgi.cgi with suspicious parameters in the filetype argument.</li>
<li>Implement access control lists on edge firewalls to restrict access to the web management interface of affected TOTOLINK routers to trusted IP ranges only.</li>
<li>Audit network logs for anomalous outbound connections originating from router infrastructure.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>cve-2026-91853</category><category>network-security</category></item></channel></rss>