OS Command Injection Vulnerability in Totolink A7100RU Router
CVE-2026-6114
Key Information:
Badges
What is CVE-2026-6114?
A security flaw has been identified in the Totolink A7100RU router's CGI Handler, specifically within the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi. This vulnerability arises from improper handling of the argument 'proto', allowing attackers to perform OS command injections remotely. With this exploit now publicly available, it poses a significant risk to users of this device, necessitating prompt attention to possible mitigations.
Affected Version(s)
A7100RU 7.4cu.2313_b20191024
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
