CVE-2026-6025Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-10); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-20: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-10: 4Technical Details · 2026-04-20: 104-1004-1104-20
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
Exploit
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-104
Disclosure2Exploit1Patch1
2026-04-111
Disclosure1
2026-04-201
Patch1
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6025 — CVSS 9.8/10 ██████████ A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/0mJNsVXD5M

    Post summary

    CVE-2026-6025 is a critical vulnerability affecting Totolink routers, with a patch now available.

    1000031
    16 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-6025 (CVSS 9.8) - OS Command Injection in Totolink A7100RU router. Remote exploit publicly available. Patch immediately or isolate affected devices. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/AjGh4Lf8OQ

    Post summary

    The tweet alerts that CVE‑2026‑6025 is a critical OS command injection in Totolink routers, that a publicly available exploit exists, and urges users to patch or isolate immediately.

    0000058
    26 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6025 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6025 #CVE-2026-6025 #CVE #Critical #CyberSecurity #InfoSec https://t.co/AbB2VsEUGx

    Post summary

    The tweet announces CVE‑2026‑6025 as a critical vulnerability (CVSS 9.8) and directs readers to the NVD for more information.

    0000033
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6025 A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Ha… https://www.cve.org/CVERecord?id=CVE-2026-6025

    Post summary

    CVE-2026-6025 is a newly disclosed vulnerability in Totolink A7100RU affecting the setSyslogCfg function in cgi-bin/cstecgi.cgi, with technical details provided but no PoC or exploitation evidence.

    0000094
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6025: CRITICAL] Vulnerability in Totolink A7100RU 7.4cu.2313_b20191024 allows remote OS command injection via CGI Handler, risking cybersecurity. Stay informed and protected!#cve,CVE-2026-6025,#cybersecurity https://cvefind.com/CVE-2026-6025

    Post summary

    The post announces a critical OS command injection vulnerability in the Totolink A7100RU router, providing a brief description but no exploit details or patch information.

    0000032
    619 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-6025: Totolink A7100RU... Unauthenticated RCE via syslog config on Totolink routers - public exploit available for 9.3 CVSS router pwning. #RouterPwn #RCE #IoTSec. https://zerodaysignal.com/vulnerability/CVE-2026-6025 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑6025 is an unauthenticated remote code execution flaw in Totolink A7100RU routers, rated CVSS 9.3, with a public exploit already available on ZerodaySignal, though no patch information is provided.

    0000067
    204 followersView on X

Explore more