Junglewise Threat Intelligence

CVE-2026-6132: Totolink A7100RU command injection in setLedCfg

CVE-2026-6132 · Severity: critical · CVSS 9.8 · Published 2026-04-12

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take full control of the router by sending a specially crafted request to the device's management interface. This could lead to the theft of sensitive data, interception of network traffic, or a complete shutdown of internet services for the user.

Technical details

An OS command injection vulnerability exists in the 'setLedCfg' function within the '/cgi-bin/cstecgi.cgi' component of the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024). The vulnerability stems from improper sanitization of the 'enable' parameter. This user-provided value is passed to 'snprintf' and subsequently executed via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary system commands. A public exploit (PoC) has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-12: disclosed: Vulnerability details and PoC published on GitHub
  • 2026-04-12: advisory: NVD and VulDB published advisory records

References