CVE-2026-6138: Totolink A7100RU CGI cstecgi.cgi setAccessDeviceCfg os command injection
A flaw has been found in Totolink A7100RU 7.4cu.2313b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mac causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6138?
CVE-2026-6138 has been classified with a high severity rating due to the potential for remote code execution through OS command injection.
How do I fix CVE-2026-6138?
To fix CVE-2026-6138, it is recommended to update the Totolink A7100RU to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2026-6138?
CVE-2026-6138 is an OS command injection vulnerability found in the CGI Handler of Totolink A7100RU.
What version of Totolink A7100RU is affected by CVE-2026-6138?
CVE-2026-6138 specifically affects Totolink A7100RU version 7.4cu.2313_b20191024.
What is the impact of CVE-2026-6138?
The impact of CVE-2026-6138 allows attackers to execute arbitrary commands on the affected device, potentially compromising its security.