CVE-2026-6140: Totolink A7100RU CGI cstecgi.cgi UploadFirmwareFile os command injection
A vulnerability was found in Totolink A7100RU 7.4cu.2313b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument FileName results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6140?
CVE-2026-6140 has a critical severity due to the potential for remote code execution via command injection.
How do I fix CVE-2026-6140?
To fix CVE-2026-6140, update the Totolink A7100RU to the latest firmware version that addresses this vulnerability.
What products are affected by CVE-2026-6140?
CVE-2026-6140 affects the Totolink A7100RU device running version 7.4cu.2313_b20191024.
What type of vulnerability is CVE-2026-6140?
CVE-2026-6140 is classified as an OS Command Injection vulnerability.
Can CVE-2026-6140 be exploited remotely?
Yes, CVE-2026-6140 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected device.