CVE-2026-6195: Totolink A7100RU CGI cstecgi.cgi setPasswordCfg os command injection
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6195?
CVE-2026-6195 has a high severity due to its potential for remote code execution via OS command injection.
How do I fix CVE-2026-6195?
To fix CVE-2026-6195, update the firmware of the Totolink A7100RU to the latest version provided by the manufacturer.
What systems are affected by CVE-2026-6195?
CVE-2026-6195 specifically affects the Totolink A7100RU model running firmware version 7.4cu.2313_b20191024.
What type of vulnerability is CVE-2026-6195?
CVE-2026-6195 is an OS command injection vulnerability found in the CGI handler of the Totolink A7100RU.
How can attackers exploit CVE-2026-6195?
Attackers can exploit CVE-2026-6195 by sending crafted requests to the setPasswordCfg function, allowing execution of arbitrary commands on the affected device.