CVE-2026-6026: Totolink A7100RU CGI cstecgi.cgi setPortalConfWeChat os command injection
A security flaw has been discovered in Totolink A7100RU 7.4cu.2313b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument enable results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6026?
CVE-2026-6026 is considered a critical vulnerability due to the potential for OS command injection.
How do I fix CVE-2026-6026?
To fix CVE-2026-6026, update the Totolink A7100RU to a version that addresses the vulnerability, if available.
What is affected by CVE-2026-6026?
CVE-2026-6026 affects the Totolink A7100RU router running firmware version 7.4cu.2313_b20191024.
What can an attacker do with CVE-2026-6026?
An attacker can exploit CVE-2026-6026 to execute arbitrary OS commands on the affected device.
Is CVE-2026-6026 exploitable remotely?
Yes, CVE-2026-6026 is exploitable remotely if the vulnerable service is accessible over the network.