CVE-2026-5690
published 2026-04-06CVE-2026-5690: A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. Executing a…
PriorityP355high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
1.46%
70.7th percentile
A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | external-secrets_external-secrets | >= 0.20.2 < 1.2.0 | 1.2.0 |
| totolink | a7100ru | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wvc4-2vwc-mwh2: A flaw has been found in Totolink A7100RU 7
ghsa_unreviewed·2026-04-07
CVE-2026-5690 [MEDIUM] CWE-77 GHSA-wvc4-2vwc-mwh2: A flaw has been found in Totolink A7100RU 7
A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.
GHSA
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
ghsa·2026-01-20
CVE-2026-22822 [CRITICAL] CWE-863 External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
### Summary
The `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to fetch secrets cross-namespaces with the roleBinding of the external-secrets controller, bypassing our security mechanisms.
This function was completely removed, as everything done with that templating function can be done in a different way while respecting our safeguards (for example, using `sourceRef` like explained here: https://github.com/external-secrets/external-secrets/issues/5690#issuecomment-3630977865)
### Impact
- Cross-namespace secret access: Attackers or misconfigured resources could retrieve secrets from namespaces other than the o
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-06
Published