Description
A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-04-10
Score: 9.3 Critical
EPSS: 2.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in Totolink A7100RU firmware allows OS command injection through the setUrlFilterRules function in /cgi-bin/cstecgi.cgi. The enable argument can be manipulated to execute arbitrary shell commands on the router, providing an attacker with full control. The description states that the attack can be launched remotely and that an exploit tool is publicly available, indicating that no local privilege or authentication is required to abuse the flaw.

Affected Systems

The vulnerability is documented for firmware version 7.4cu.2313_b20191024 of the Totolink A7100RU router. Other revisions are not explicitly confirmed or denied, so additional builds may also be affected unless they contain the patch identified in the vendor references.

Risk and Exploitability

The CVSS base score of 9.3 signals critical severity, while the EPSS score of 2% suggests a moderate likelihood of exploitation. The flaw is not listed in CISA KEV but its remote nature, high impact, availability of public exploitation code, and lack of authentication requirements create a compelling risk for any affected router.

Generated by OpenCVE AI on June 18, 2026 at 09:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router to the latest firmware release posted by Totolink that contains the command‑injection fix; consult the vendor site or the reference documentation for the corrected build.
  • If a patch is not yet released, block external access to the /cgi-bin/cstecgi.cgi endpoint using firewall rules or access‑control lists to limit exposure to the vulnerable CGI handler.
  • Enable detailed logging on the router or a connected network monitor and look for anomalous CGI activity or unexpected shell command execution.

Generated by OpenCVE AI on June 18, 2026 at 09:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a7100ru
Vendors & Products Totolink a7100ru

Fri, 10 Apr 2026 06:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A7100RU CGI cstecgi.cgi setUrlFilterRules os command injection
First Time appeared Totolink
Totolink a7100ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a7100ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a7100ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A7100ru A7100ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-14T14:35:29.203Z

Reserved: 2026-04-09T15:55:23.724Z

Link: CVE-2026-6027

cve-icon Vulnrichment

Updated: 2026-04-14T14:35:25.113Z

cve-icon NVD

Status : Deferred

Published: 2026-04-10T07:16:21.583

Modified: 2026-06-17T11:00:11.330

Link: CVE-2026-6027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T09:30:15Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')