9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.
AI Analysis
OS command injection vulnerability in Totolink A7100RU via the setAppCfg function in the CGI Handler
Basic Information
ID
CVE-2026-6115
Source
VulDB
Published
Apr 12, 2026 at 04:00
Affected Product
Vendor
Totolink
Product
A7100RU
Version
7.4cu.2313_b20191024
Affected Versions
Totolink A7100RU 7.4cu.2313_b20191024
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Totolink
Product
A7100RU
Version
7.4cu.2313_b20191024