CVE-2026-6028Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-10); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-10: 2Exploit Tool / Code · 2026-04-10: 2Technical Details · 2026-04-10: 3Technical Details · 2026-04-11: 104-1004-11
Signal classification3 categories
Disclosure
240.0%
Exploit
240.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-104
Disclosure1Exploit2General1
2026-04-111
Disclosure1
Full discourse5 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6028 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6028 #CVE-2026-6028 #CVE #Critical #CyberSecurity #InfoSec https://t.co/TgMTab5K4U

    Post summary

    The tweet announces CVE-2026-6028 as a new, critical vulnerability, citing its severity and directing readers to the NVD for details.

    0000036
    125 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-6028: Totolink A7100RU CGI cstecgi.cgi ... Remote RCE via setPptpServerCfg enable param - ancient Totolink firmware with public exploit makes this a sitting duck f... https://zerodaysignal.com/vulnerability/CVE-2026-6028 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑6028, highlighting a remote RCE via a specific parameter in Totolink’s cstecgi.cgi and noting a public exploit, but it does not confirm active attacks or provide patch information.

    0000054
    204 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6028 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the c… https://www.cve.org/CVERecord?id=CVE-2026-6028

    Post summary

    The post merely notes the existence of CVE‑2026‑6028 for Totolink A7100RU and links to the CVE record, offering no further details about exploitation or remediation.

    0000093
    57.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Exploit

    ```json { "x": "🚨 CRITICAL: CVE-2026-6028 (CVSS 9.8)\nTotolink A7100RU router vulnerable to remote OS command injection via CGI handler. Exploit publicly available. https://t.co/ArFjrMpglE

    Post summary

    A critical remote OS command injection vulnerability (CVE-2026-6028) in Totolink A7100RU routers is reported with an available exploit and a link to further details.

    0000029
    6 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6028: CRITICAL] Security alert: Totolink A7100RU 7.4cu.2313_b20191024 has a vulnerability impacting setPptpServerCfg function in /cgi-bin/cstecgi.cgi, allowing OS command injection remotely.#cve,CVE-2026-6028,#cybersecurity https://cvefind.com/CVE-2026-6028

    Post summary

    The alert announces a critical OS command injection vulnerability in Totolink A7100RU router's setPptpServerCfg function, without evidence of exploitation or patch updates.

    0000051
    619 followersView on X

Explore more