
#RCE attempt targeting TOTOLINK routers (CVE-2026-1157) 2026-04-09 20:17:31 UTC Source IP: 176.65.139.60 🇩🇪 POST /cgi-bin/cstecgi.cgi IOCs: 103.130.214.71 🇻🇳 hxxp://103.130.214.71:1212/cat.sh 56c7916816349aebe450a16257b8448c https://t.co/uWLpPZaZUg
Post summary
The post documents an active remote code execution attempt against TOTOLINK routers, referencing a linked script that likely serves as a PoC/exploit, with no patch or mitigation information provided.
