CVE-2026-6028: Totolink A7100RU CGI cstecgi.cgi setPptpServerCfg os command injection
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313b20191024. Impacted is the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6028?
CVE-2026-6028 has a severity score of 8.9, indicating a high risk of exploitation.
What vulnerability does CVE-2026-6028 exploit?
CVE-2026-6028 exploits an OS command injection vulnerability in the setPptpServerCfg function of the Totolink A7100RU.
How do I fix CVE-2026-6028?
To fix CVE-2026-6028, update the firmware of your Totolink A7100RU to the latest version provided by the manufacturer.
Can CVE-2026-6028 be exploited remotely?
Yes, CVE-2026-6028 allows attackers to execute commands remotely through OS command injection.
What are the potential impacts of CVE-2026-6028?
Exploitation of CVE-2026-6028 may lead to unauthorized access, data leakage, or system compromise.