CVE-2026-6156: Totolink A7100RU CGI cstecgi.cgi setIpQosRules os command injection
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313b20191024. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument Comment leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6156?
CVE-2026-6156 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-6156?
To fix CVE-2026-6156, update the Totolink A7100RU firmware to the latest version that addresses this vulnerability.
What impact does CVE-2026-6156 have on the device?
CVE-2026-6156 allows attackers to execute arbitrary commands on the affected Totolink A7100RU device.
Which versions of Totolink A7100RU are affected by CVE-2026-6156?
CVE-2026-6156 affects Totolink A7100RU version 7.4cu.2313_b20191024.
What component is vulnerable in CVE-2026-6156?
The vulnerability in CVE-2026-6156 is found in the CGI Handler, specifically in the setIpQosRules function located in /cgi-bin/cstecgi.cgi.