PT-2026-32489 · Totolink · A7100Ru

·

CVE-2026-6195

·

Published

2026-04-05

·

Updated

2026-04-19

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink A7100RU version 7.4cu.2313 b20191024
Description A security issue in the CGI Handler component allows for remote OS command injection. The problem exists in the setPasswordCfg() function within the '/cgi-bin/cstecgi.cgi' file. An unauthenticated attacker can exploit this by manipulating the admpass variable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/cgi-bin/cstecgi.cgi' file or disable the setPasswordCfg() function to minimize the risk of exploitation.

Exploit

RCE

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07602
CVE-2026-6195

Affected Products

A7100Ru