Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.9

Totolink A7100RU Router: Remote Command Execution Risk

CVE-2026-6112
Summary

The Totolink A7100RU router's CGI Handler is vulnerable to a remote attack that can allow an attacker to execute commands on the router. This could be used to take control of the router or disrupt its functioning. Update the router's software to the latest version to fix this issue.

Original title
A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the...
Original description
A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
nvd CVSS2.0 10.0
nvd CVSS3.1 9.8
nvd CVSS4.0 8.9
Vulnerability type
CWE-77 Command Injection
CWE-78 OS Command Injection
Published: 12 Apr 2026 · Updated: 12 Apr 2026 · First seen: 12 Apr 2026