9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
AI Analysis
OS command injection vulnerability in Totolink A7100RU via the setDiagnosisCfg function in the /cgi-bin/cstecgi.cgi file, allowing remote exploitation.
Basic Information
ID
CVE-2026-6116
Source
VulDB
Published
Apr 12, 2026 at 04:15
Affected Product
Vendor
Totolink
Product
A7100RU
Version
7.4cu.2313_b20191024
Affected Versions
Totolink A7100RU 7.4cu.2313_b20191024
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Totolink
Product
A7100RU
Version
7.4cu.2313_b20191024