9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument enable results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
AI Analysis
OS command injection vulnerability in Totolink A7100RU via the setPortalConfWeChat function in the CGI Handler
Basic Information
ID
CVE-2026-6026
Source
VulDB
Published
Apr 10, 2026 at 05:45
Modified
Apr 10, 2026 at 11:52
Affected Product
Vendor
Totolink
Product
A7100RU
Version
7.4cu.2313_b20191024
Affected Versions
Totolink A7100RU 7.4cu.2313_b20191024
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Totolink
Product
A7100RU
Version
7.4cu.2313_b20191024