Junglewise Threat Intelligence

CVE-2026-6139: Totolink A7100RU command injection in UploadOpenVpnCert

CVE-2026-6139 · Severity: critical · CVSS 9.8 · Published 2026-04-13

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A7100RU home router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted network request. This could allow an unauthorized user to monitor internet traffic, disrupt network services, or use the device as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the CGI handler component. The vulnerability is located in the 'UploadOpenVpnCert' function in '/cgi-bin/cstecgi.cgi'. The root cause is the improper neutralization of the 'FileName' parameter; the application uses 'snprintf' to insert this user-controlled string into a buffer that is subsequently executed via 'execv' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'FileName' field to execute arbitrary commands with elevated privileges. Public exploit code (PoC) demonstrating a 'wget' callback has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-13: advisory: NVD publication date

References