CVE-2026-6139: Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection
A vulnerability has been found in Totolink A7100RU 7.4cu.2313b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6139?
The severity of CVE-2026-6139 is classified as high due to the potential for unauthorized command execution.
How do I fix CVE-2026-6139?
To fix CVE-2026-6139, update the firmware of the Totolink A7100RU to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2026-6139?
CVE-2026-6139 is an OS command injection vulnerability that can be exploited through the CGI handler on the affected device.
Which devices are affected by CVE-2026-6139?
CVE-2026-6139 affects the Totolink A7100RU device running version 7.4cu.2313_b20191024.
What can attackers achieve by exploiting CVE-2026-6139?
By exploiting CVE-2026-6139, attackers can execute arbitrary commands on the device, potentially compromising its security.