Description
A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument User results in os command injection. The attack may be launched remotely. The exploit is now public and may be used.
Published: 2026-04-10
Score: 9.3 Critical
EPSS: 3.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the setVpnAccountCfg function of the /cgi-bin/cstecgi.cgi CGI handler on the Totolink A7100RU router. An attacker can inject arbitrary operating‑system commands through the User parameter, allowing remote execution of code on the device’s underlying firmware environment. The flaw is exploitable from outside the local network and is listed as publicly known, meaning reasonable attackers can craft and send a malicious request to trigger the vulnerability.

Affected Systems

The vulnerability affects Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024. Devices running any other firmware revision are not identified as affected in the given data.

Risk and Exploitability

The CVSS score of 9.3 designates the issue as critical in severity. An EPSS score of 3% suggests a moderate likelihood of exploitation in the current time window. The exploit is publicly available, but the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote, targeting the router’s publicly exposed CGI interface; no explicit authentication requirement is stated, so the assumption is that the request can be made without prior login.

Generated by OpenCVE AI on June 18, 2026 at 09:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version that contains the fix for the setVpnAccountCfg command injection.
  • If a firmware update is not available, block external traffic to the /cgi-bin/cstecgi.cgi URI or restrict the router’s management interface to trusted networks by firewall rules.
  • Simplify or disable the vulnerable CGI handler if the router’s configuration allows it, or otherwise isolate the device from the internet until a patch is applied.

Generated by OpenCVE AI on June 18, 2026 at 09:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a7100ru
Vendors & Products Totolink a7100ru

Fri, 10 Apr 2026 07:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument User results in os command injection. The attack may be launched remotely. The exploit is now public and may be used.
Title Totolink A7100RU CGI cstecgi.cgi setVpnAccountCfg os command injection
First Time appeared Totolink
Totolink a7100ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a7100ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a7100ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A7100ru A7100ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-10T15:45:55.950Z

Reserved: 2026-04-09T15:55:29.603Z

Link: CVE-2026-6029

cve-icon Vulnrichment

Updated: 2026-04-10T15:45:49.133Z

cve-icon NVD

Status : Deferred

Published: 2026-04-10T07:16:22.000

Modified: 2026-06-17T11:00:11.640

Link: CVE-2026-6029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T09:30:15Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')