Description
A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-04-12
Score: 9.3 Critical
EPSS: 3.3% Low
KEV: No
Impact: Remote OS command execution via CGI command injection
Action: Patch immediately
AI Analysis

Impact

The vulnerability allows an attacker to inject arbitrary operating system commands through the maxRtrAdvInterval parameter of the setRadvdCfg function in the cstecgi.cgi CGI handler. This results in remote OS command execution and full compromise of the affected router, giving the attacker control of the device. Based on the router's role, this control could extend to networks configured via the router, but that expansion is inferred from typical router behavior and is not explicitly stated in the disclosure.

Affected Systems

Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024 are affected. No other versions or products are listed as vulnerable in the available data.

Risk and Exploitability

The flaw scores a CVSS of 9.3, indicating critical severity. EPSS is 3%, suggesting a moderate exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. Attackers can initiate the exploit remotely by sending a crafted request to the /cgi-bin/cstecgi.cgi endpoint with a malicious maxRtrAdvInterval parameter. The likely attack vector is therefore remote network traffic; this inference is based on the description that the exploit can be initiated remotely. Successful exploitation results in remote OS command execution, leading to complete loss of confidentiality, integrity, and availability of the affected device.

Generated by OpenCVE AI on September 26, 2026 at 08:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Totolink that addresses the setRadvdCfg command injection flaw.
  • If no update is available, disable the /cgi-bin/cstecgi.cgi endpoint or block external access to the port hosting the CGI interface.
  • Monitor the router's system and network logs for suspicious activity, and consider network segmentation to limit exposure.

Generated by OpenCVE AI on September 26, 2026 at 08:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a7100ru
Vendors & Products Totolink a7100ru

Sun, 12 Apr 2026 04:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink A7100RU CGI cstecgi.cgi setRadvdCfg os command injection
First Time appeared Totolink
Totolink a7100ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a7100ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a7100ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A7100ru A7100ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-15T15:17:02.716Z

Reserved: 2026-04-11T08:17:59.227Z

Link: CVE-2026-6112

cve-icon Vulnrichment

Updated: 2026-04-15T15:16:58.437Z

cve-icon NVD

Status : Deferred

Published: 2026-04-12T04:16:47.133

Modified: 2026-06-17T11:00:18.810

Link: CVE-2026-6112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T09:00:14Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')