CVE-2026-6027: Totolink A7100RU CGI cstecgi.cgi setUrlFilterRules os command injection
A weakness has been identified in Totolink A7100RU 7.4cu.2313b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6027?
CVE-2026-6027 has a high severity rating of 8.9.
How does CVE-2026-6027 exploit OS command injection?
CVE-2026-6027 exploits OS command injection by manipulating the argument 'enable' in the setUrlFilterRules function.
What are the potential impacts of CVE-2026-6027?
The impact of CVE-2026-6027 includes unauthorized command execution, leading to potential system compromise.
Which device is affected by CVE-2026-6027?
CVE-2026-6027 affects the Totolink A7100RU device running firmware version 7.4cu.2313_b20191024.
How can I mitigate the risk associated with CVE-2026-6027?
To mitigate the risk of CVE-2026-6027, update the firmware of the Totolink A7100RU device to the latest version that addresses this vulnerability.