CVE-2026-5030 | Totolink NR1800X 9.1.0u.6279_B20210910 Telnet Service /cgi-bin/cstecgi.cgi NTPSyncWithHost host_time command injection
A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection.
This vulnerability is documented as CVE-2026-5030. The attack can be initiated remotely. Additionally, an exploit exists.