
🚨 Critical CVEs Today: Totolink CGI Handler Risks (CVSS 9.8-9.8) Affected: Totolink A7100RU; CF Image Hosting Script Internet-facing exposure dominates as remote CGI vulnerabilities enable command execution and data exposure. • CVE-2026-6112 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setRadvdCfg allows manipulation of maxRtrAdvInterval to enable OS command injection; remote exploitation possible. • CVE-2026-6113 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setTtyServiceCfg enables manipulation of ttyEnable causing OS command injection; remote exploitation possible. • CVE-2026-6114 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setNetworkCfg manipulation of proto leads to OS command injection; remote exploitation possible. • CVE-2019-25709 (CVSS 9.8) CF Image Hosting Script 1.6.5; Unauthenticated attackers can download and decode the application database by accessing imgdb.db in upload/data, exposing delete IDs that enable mass deletion of pictures. Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion
Post summary
The post announces several critical CVEs affecting Totolink routers and a CF Image Hosting script, detailing command injection vulnerabilities and urging immediate patching and mitigation.


