CVE-2026-6156

CRITICAL

Totolink A7100RU CGI cstecgi.cgi setIpQosRules os command injection

Title source: cna

Description

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument Comment leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Scores

CVSS v3 9.8
EPSS 0.0125
EPSS Percentile 79.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
Totolink/A7100RU 7.4cu.2313_b20191024
Published Apr 13, 2026
Tracked Since Apr 13, 2026