PT-2026-32197 · Totolink · A7100Ru

Ltzhuster

·

Published

2026-04-13

·

Updated

2026-04-14

·

CVE-2026-6139

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink A7100RU version 7.4cu.2313 b20191024
Description A flaw exists in the CGI Handler component of Totolink A7100RU version 7.4cu.2313 b20191024. Specifically, the UploadOpenVpnCert function within the /cgi-bin/cstecgi.cgi file is susceptible to os command injection through manipulation of the FileName argument. This allows for remote execution of commands. The exploit for this issue has been publicly disclosed.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6139

Affected Products

A7100Ru