CVE-2026-6155: Totolink A7100RU CGI cstecgi.cgi setWanCfg os command injection
A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument pppoeServiceName can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6155?
CVE-2026-6155 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-6155?
To fix CVE-2026-6155, update the Totolink A7100RU router firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2026-6155?
CVE-2026-6155 is an OS command injection vulnerability affecting the setWanCfg function.
Who is affected by CVE-2026-6155?
Users of the Totolink A7100RU router running firmware version 7.4cu.2313 are affected by CVE-2026-6155.
What can attackers do with CVE-2026-6155?
Attackers exploiting CVE-2026-6155 can execute arbitrary commands on the affected router, potentially gaining full control.