CVE-2026-6114: Totolink A7100RU CGI cstecgi.cgi setNetworkCfg os command injection
A vulnerability was detected in Totolink A7100RU 7.4cu.2313b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument proto results in os command injection. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6114?
CVE-2026-6114 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-6114?
To fix CVE-2026-6114, update the Totolink A7100RU firmware to the latest version that addresses this vulnerability.
What kind of vulnerability is CVE-2026-6114?
CVE-2026-6114 is an OS command injection vulnerability that allows attackers to execute arbitrary commands on the affected device.
Which devices are affected by CVE-2026-6114?
CVE-2026-6114 affects the Totolink A7100RU router running firmware version 7.4cu.2313_b20191024.
Could CVE-2026-6114 be exploited remotely?
Yes, CVE-2026-6114 can be exploited remotely, allowing unauthorized users to potentially gain access to the affected system.