CVE-2026-6026Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument enable results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-04-10); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-10: 5Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-10: 2Patch / Workaround · 2026-04-10: 2Technical Details · 2026-04-10: 504-1004-11
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
Exploit
116.7%
PoC
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-105
Disclosure1Exploit1Patch2PoC1
2026-04-111
Disclosure1
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6026 — CVSS 9.8/10 ██████████ A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/VzOcIoJuUv

    Post summary

    CVE‑2026‑6026 is a critical flaw in the Totolink A7100RU router (CVSS 9.8/10) and a patch has already been released.

    1000036
    16 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6026 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6026 #CVE-2026-6026 #CVE #Critical #CyberSecurity #InfoSec https://t.co/OZ37zP2urX

    Post summary

    The tweet announces a new CVE-2026‑6026 with critical severity, but offers no technical details, PoC, exploit, or mitigation guidance.

    0000035
    125 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6026: Totolink A7100RU CGI cstecgi.cgi ... Unauthenticated RCE via WeChat portal config - exploit code already public, 9.3 CVSS means instant botnet fodder for the... https://zerodaysignal.com/vulnerability/CVE-2026-6026 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces that exploit code for CVE-2026-6026 is publicly available, confirming the existence of a PoC and detailing the vulnerability as a high‑severity unauthenticated RCE.

    0000050
    204 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6026 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.c… https://www.cve.org/CVERecord?id=CVE-2026-6026

    Post summary

    A new CVE (CVE-2026-6026) affecting the Totolink A7100RU router’s setPortalConfWeChat function has been reported, with a link to the CVE record but no PoC or exploit details.

    0000091
    57.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-6026 (CVSS 9.8) - Totolink A7100RU router vulnerable to remote OS command injection via CGI Handler. No authentication required. Exploit public. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/MiCmmHoBtL

    Post summary

    CVE‑2026‑6026 is a critical OS command‑injection vulnerability in the Totolink A7100RU router, no authentication needed; users should patch immediately.

    0000045
    10 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-6026: CRITICAL] Security flaw in Totolink A7100RU 7.4cu.2313_b20191024 allows remote os command injection through cgi-bin/cstecgi.cgi. Public exploit available - beware of attacks.#cve,CVE-2026-6026,#cybersecurity https://cvefind.com/CVE-2026-6026

    Post summary

    The post highlights a critical command injection flaw in Totolink A7100RU routers, warns of a public exploit, and urges users to be vigilant about possible attacks.

    0000034
    619 followersView on X

Explore more