Junglewise Threat Intelligence

CVE-2026-6115: Totolink A7100RU command injection in cstecgi.cgi

CVE-2026-6115 · Severity: critical · CVSS 9.8 · Published 2026-04-12

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability has been identified in the Totolink A7100RU home router. This flaw allows an attacker to remotely take full control of the device by sending a specially crafted web request. Successful exploitation could lead to the theft of sensitive data, interception of internet traffic, or the use of the router as a foothold for further attacks on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the CGI handler component. The flaw is located in the 'setAppCfg' function of the '/cgi-bin/cstecgi.cgi' script. The application fails to properly sanitize the 'enable' argument before passing it to the 'Uci_Set_Str' and 'CsteSystem' functions, where it is eventually executed via 'execv()'. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the JSON payload. This allows for full system compromise with root privileges. A public exploit (PoC) has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-12: disclosed: Vulnerability details and PoC published via GitHub and VulDB
  • 2026-04-12: advisory: CVE-2026-6115 published to NVD

References