PT-2026-31886 · Totolink · Totolink A7100Ru
Ltzhust
·
Published
2026-03-28
·
Updated
2026-04-11
·
CVE-2026-6028
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Totolink A7100RU version 7.4cu.2313 b20191024
Description
A security issue exists in the Totolink A7100RU router. The
setPptpServerCfg function within the /cgi-bin/cstecgi.cgi file, part of the CGI Handler component, is susceptible to OS command injection through the enable parameter. This allows for remote execution of commands. The vulnerability has been publicly disclosed and an exploit is available.Recommendations
For Totolink A7100RU version 7.4cu.2313 b20191024, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Totolink A7100Ru