A remote OS command injection vulnerability exists in the Totolink A7100RU CGI handler, allowing unauthenticated attackers to execute commands via the...
Description
A remote OS command injection vulnerability exists in the Totolink A7100RU CGI handler, allowing unauthenticated attackers to execute commands via the enable argument in setPortalConfWeChat.
AI Analyst Comment
Remediation
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Totolink
PRODUCT: A7100RU
AFFECTED_VERSIONS: 7.4cu.2313_b20191024
---END_METADATA---
Description Summary:
A remote OS command injection vulnerability exists in the Totolink A7100RU CGI handler, allowing unauthenticated attackers to execute commands via the enable argument in setPortalConfWeChat.
Executive Summary:
A critical remote OS command injection flaw in the Totolink A7100RU router allows unauthenticated attackers to execute arbitrary commands, threatening network integrity.
Vulnerability Details
CVE-ID: CVE-2026-6026
Affected Software: Totolink A7100RU
Affected Versions: 7.4cu.2313_b20191024
Vulnerability: The vulnerability is located in the
setPortalConfWeChatfunction of the/cgi-bin/cstecgi.cgicomponent. Unauthenticated remote attackers can perform OS command injection by manipulating theenableargument.Business Impact
The CVSS score of 9.8 justifies the classification of this vulnerability as critical. Successful exploitation provides attackers with arbitrary code execution capabilities, which can be leveraged to compromise the device, perform man-in-the-middle attacks, or facilitate further unauthorized access to the protected network.
Remediation Plan
Immediate Action: Update the affected Totolink A7100RU devices to the latest firmware provided by the manufacturer.
Proactive Monitoring: Monitor network traffic for suspicious requests to the CGI handler and review device logs for signs of unauthorized configuration changes or command execution.
Compensating Controls: Restrict management interface access to trusted networks and monitor for unauthorized attempts to invoke the vulnerable CGI function.
Exploitation Status
Public Exploit Available: Yes
Analyst Notes: As of April 10, 2026, public exploit code is available. The ability for unauthenticated remote attackers to trigger this command injection makes it an urgent security priority.
Analyst Recommendation
Given the critical severity and the existence of public exploits, immediate remediation is required. Organizations should ensure all affected hardware is updated to the latest available firmware to mitigate this high-risk vulnerability.