CVE-2026-6131: Totolink A7100RU CGI cstecgi.cgi setTracerouteCfg os command injection
A vulnerability was found in Totolink A7100RU 7.4cu.2313b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument command results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6131?
CVE-2026-6131 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2026-6131?
To fix CVE-2026-6131, update the Totolink A7100RU firmware to the latest version available from the manufacturer.
What does CVE-2026-6131 impact?
CVE-2026-6131 impacts the CGI Handler specifically in the setTracerouteCfg function of the Totolink A7100RU router.
Can CVE-2026-6131 be exploited remotely?
Yes, CVE-2026-6131 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected device.
What version of Totolink A7100RU is affected by CVE-2026-6131?
CVE-2026-6131 affects Totolink A7100RU version 7.4cu.2313_b20191024.