CVE-2026-6112: Totolink A7100RU CGI cstecgi.cgi setRadvdCfg os command injection
A weakness has been identified in Totolink A7100RU 7.4cu.2313b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6112?
CVE-2026-6112 has been classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2026-6112?
To fix CVE-2026-6112, update the Totolink A7100RU firmware to the latest version provided by the manufacturer.
What impact does CVE-2026-6112 have on affected devices?
CVE-2026-6112 allows attackers to execute arbitrary commands on the device, potentially compromising its security.
Which version of Totolink A7100RU is affected by CVE-2026-6112?
CVE-2026-6112 specifically affects Totolink A7100RU version 7.4cu.2313_b20191024.
What component is vulnerable in CVE-2026-6112?
The vulnerability CVE-2026-6112 is found in the CGI Handler component of the cstecgi.cgi file.