CVE-2026-6025: Totolink A7100RU CGI cstecgi.cgi setSyslogCfg os command injection
A vulnerability was identified in Totolink A7100RU 7.4cu.2313b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6025?
CVE-2026-6025 is rated as a high severity vulnerability due to the potential for remote code execution through OS command injection.
How do I fix CVE-2026-6025?
To mitigate CVE-2026-6025, update the Totolink A7100RU firmware to the latest version that addresses this vulnerability.
What components are affected by CVE-2026-6025?
CVE-2026-6025 affects the CGI Handler component within the Totolink A7100RU firmware version 7.4cu.2313_b20191024.
What type of attack does CVE-2026-6025 allow?
CVE-2026-6025 allows attackers to exploit the setSyslogCfg function, potentially leading to remote command execution.
Is CVE-2026-6025 specific to any version of the Totolink A7100RU?
Yes, CVE-2026-6025 specifically targets the Totolink A7100RU version 7.4cu.2313_b20191024.