Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.9

Totolink A7100RU Firmware Upload Function Allows Remote Attack

CVE-2026-6140
Summary

A security flaw in the Totolink A7100RU's firmware upload function allows hackers to potentially take control of the device remotely. This could happen if someone with malicious intent sends a specially crafted file to the device. To protect your device, update to the latest firmware version as soon as possible.

Original title
A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipula...
Original description
A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument FileName results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used.
nvd CVSS2.0 10.0
nvd CVSS3.1 9.8
nvd CVSS4.0 8.9
Vulnerability type
CWE-77 Command Injection
CWE-78 OS Command Injection
Published: 13 Apr 2026 · Updated: 13 Apr 2026 · First seen: 13 Apr 2026