Description
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-04-13
Score: 9.3 Critical
EPSS: 14.3% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the flaw resides in the setPasswordCfg method of /cgi-bin/cstecgi.cgi used by Totolink A7100RU routers. By tampering with the admpass parameter, an attacker can inject arbitrary operating‑system commands, which the device executes. The description indicates that this injection results in unauthorized command execution; it is inferred that the attacker gains full device control, enabling configuration changes, data exfiltration, or service disruption, which compromises confidentiality, integrity, and availability.

Affected Systems

Based on the description, affected devices are Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024. The vulnerability exists in the setPasswordCfg CGI endpoint, meaning any router with this firmware is potentially susceptible.

Risk and Exploitability

Based on the description, the vulnerability carries a CVSS score of 9.3, indicating a critical rating, and an EPSS score of 14%, suggesting a moderate probability of exploitation. It is inferred that an attacker can trigger the injection without needing special privileges. The likely attack vector involves sending a remote HTTP request to the cstecgi.cgi endpoint from any network that can reach the router’s management interface. The issue is not yet listed in the CISA KEV catalog, which does not reduce the risk.

Generated by OpenCVE AI on June 18, 2026 at 09:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Totolink that addresses the command injection vulnerability.
  • If no update is available, restrict access to the router’s web management interface by blocking HTTP/HTTPS traffic to the device from untrusted networks or enabling VPN‑based remote management only.
  • Ensure the router’s management interface is reachable only from trusted LAN segments, and monitor logs for unusual cstecgi.cgi activity.

Generated by OpenCVE AI on June 18, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Totolink a7100ru
Vendors & Products Totolink a7100ru

Mon, 13 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Title Totolink A7100RU CGI cstecgi.cgi setPasswordCfg os command injection
First Time appeared Totolink
Totolink a7100ru Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:totolink:a7100ru_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a7100ru Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink A7100ru A7100ru Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-13T18:00:15.007Z

Reserved: 2026-04-13T08:45:05.331Z

Link: CVE-2026-6195

cve-icon Vulnrichment

Updated: 2026-04-13T17:59:59.131Z

cve-icon NVD

Status : Deferred

Published: 2026-04-13T18:16:32.353

Modified: 2026-06-17T11:00:28.010

Link: CVE-2026-6195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T09:15:16Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')