A vulnerability was determined in code-projects Simple ChatBox up to 1
Description
A vulnerability was determined in code-projects Simple ChatBox up to 1
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Totolink
PRODUCT: A7100RU
AFFECTED_VERSIONS: 7.4cu.2313_b20191024
---END_METADATA---
Description Summary:
Totolink A7100RU allows remote OS command injection via the setIpQosRules function in the CGI handler.
Executive Summary:
A critical OS command injection vulnerability in the Totolink A7100RU permits remote, unauthenticated attackers to execute arbitrary system commands.
Vulnerability Details
CVE-ID: CVE-2026-6156
Affected Software: Totolink A7100RU
Affected Versions: 7.4cu.2313_b20191024
Vulnerability: The
setIpQosRulesfunction in/cgi-bin/cstecgi.cgifails to sanitize theCommentargument, allowing an unauthenticated attacker to inject and execute OS commands.Business Impact
The CVSS score of 9.8 highlights the critical threat of this vulnerability. Successful exploitation provides the attacker with full control over the device, facilitating further network penetration and data interception.
Remediation Plan
Immediate Action: Apply the vendor-provided firmware update immediately to patch the vulnerable CGI function.
Proactive Monitoring: Monitor system logs for unusual behavior or unauthorized command execution.
Compensating Controls: Ensure the router's management interface is not accessible from the public internet by configuring appropriate firewall rules.
Exploitation Status
Public Exploit Available: True
Analyst Notes: As of Apr 13, 2026, public exploit code is available. The risk of exploitation is extremely high given the remote nature of the flaw.
Analyst Recommendation
Immediate firmware updates are required to mitigate this critical risk. Restricting access to the device management interface is a necessary secondary measure to prevent unauthorized exploitation.