CVE-2026-6113: Totolink A7100RU CGI cstecgi.cgi setTtyServiceCfg os command injection
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313b20191024. Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument ttyEnable leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6113?
CVE-2026-6113 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-6113?
To mitigate CVE-2026-6113, update the Totolink A7100RU router firmware to the latest version that addresses this vulnerability.
What does CVE-2026-6113 exploit?
CVE-2026-6113 exploits an OS command injection vulnerability in the setTtyServiceCfg function of the CGI handler.
What is affected by CVE-2026-6113?
CVE-2026-6113 affects the Totolink A7100RU router specifically running version 7.4cu.2313_b20191024.
Can CVE-2026-6113 lead to unauthorized access?
Yes, CVE-2026-6113 can lead to unauthorized access and control over the affected device.