CVE-2026-6027Disclosure

MEDIUMCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-10: 2Exploit Tool / Code · 2026-04-10: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 304-1004-11
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-103
Disclosure1Exploit1Patch1
2026-04-111
Disclosure1
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6027 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6027 #CVE-2026-6027 #CVE #Critical #CyberSecurity #InfoSec https://t.co/PxDJKUTWoe

    Post summary

    The tweet announces the existence of CVE-2026-6027 with a high severity score, but it offers no technical details, PoC, or exploitation information.

    0000134
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6027 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the compo… https://www.cve.org/CVERecord?id=CVE-2026-6027

    Post summary

    A weakness in the Totolink A7100RU router (function setUrlFilterRules) has been identified, with details available in the CVE record.

    0000087
    57.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-6027 (CVSS 9.8) Totolink A7100RU router vulnerable to unauthenticated remote OS command injection via /cgi-bin/cstecgi[.]cgi. Public exploit available. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/F3lFLRhaOe

    Post summary

    A critical CVE‑2026‑6027 vulnerability in the Totolink A7100RU router is identified with public exploit availability; users are urged to apply a patch immediately.

    0000045
    10 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-6027: CRITICAL] Critical vulnerability found in Totolink A7100RU 7.4cu.2313_b20191024! Manipulating setUrlFilterRules can trigger os command injection, allowing remote attacks. Exploit published pose...#cve,CVE-2026-6027,#cybersecurity https://cvefind.com/CVE-2026-6027

    Post summary

    The post announces a critical OS command injection vulnerability in Totolink A7100RU and indicates that an exploit has been published, allowing remote attacks.

    0000036
    619 followersView on X

Explore more