Description
A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument firewallType leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-04-06
Score: 6.9 Medium
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the setFirewallType routine of the /cgi-bin/cstecgi.cgi script on Totolink A7100RU routers. By manipulating the firewallType parameter, an attacker can inject arbitrary shell commands that the router executes with system privileges. This vulnerability, corresponding to CWE‑77 and CWE‑78, allows the attacker to take complete control over the device’s operating system, potentially compromising network traffic, device configuration, and any data passing through the router.

Affected Systems

The affected product is the Totolink A7100RU router running firmware version 7.4cu.2313_b20191024. No other firmware revisions are mentioned, so only this specific build is confirmed to be vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS v3.1 score of 6.9, indicating medium severity. The EPSS score of 1% reflects a very low but non‑zero chance of exploitation, and it is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a crafted HTTP request to the cstecgi.cgi endpoint; no additional credentials or privileged access are required. Because the attack can be performed without local access, the risk remains significant for devices exposed to untrusted networks.

Generated by OpenCVE AI on June 18, 2026 at 09:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Totolink that addresses the command injection issue.
  • If an update is not yet available, block or disable remote access to the /cgi‑bin/cstecgi.cgi endpoint or the firewall management API, limiting interaction to trusted internal users.
  • Separate the router from untrusted traffic by placing it behind a secure gateway or applying strict network segmentation.
  • Configure logging of CGI requests and monitor for anomalous parameters that may indicate attempted exploitation.

Generated by OpenCVE AI on June 18, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a7100ru
Vendors & Products Totolink a7100ru

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument firewallType leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Title Totolink A7100RU cstecgi.cgi setFirewallType os command injection
First Time appeared Totolink
Totolink a7100ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a7100ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a7100ru Firmware
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A7100ru A7100ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-07T16:24:28.803Z

Reserved: 2026-04-06T10:27:07.838Z

Link: CVE-2026-5691

cve-icon Vulnrichment

Updated: 2026-04-07T16:24:26.172Z

cve-icon NVD

Status : Deferred

Published: 2026-04-06T23:16:32.600

Modified: 2026-06-17T10:59:31.333

Link: CVE-2026-5691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T09:30:15Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')