CVE-2026-6029Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument User results in os command injection. The attack may be launched remotely. The exploit is now public and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-10); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-10: 2Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 304-1004-11
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-104
Disclosure2Patch1PoC1
2026-04-111
Disclosure1
Full discourse5 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6029 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6029 #CVE-2026-6029 #CVE #Critical #CyberSecurity #InfoSec https://t.co/AjrcXsvyw9

    Post summary

    The tweet announces a newly identified CVE‑2026‑6029 with a severity score of 9.8, but provides no additional technical detail, PoC, or evidence of exploitation.

    0000042
    125 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6029: Totolink A7100RU CGI cstecgi.cgi ... Unauthenticated RCE via User param in setVpnAccountCfg - public exploit drops you straight into router shell with zero e... https://zerodaysignal.com/vulnerability/CVE-2026-6029 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑6029 as an unauthenticated RCE in Totolink routers and highlights a publicly disclosed proof‑of‑concept that grants shell access, but offers no patch, real‑world exploitation evidence, or code details.

    0000057
    204 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6029 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the com… https://www.cve.org/CVERecord?id=CVE-2026-6029

    Post summary

    The text announces a newly detected vulnerability in the Totolink A7100RU router, identifying the affected function and file, but does not provide detailed technical specs, exploits, or remediation.

    0000087
    57.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-6029 (CVSS 9.8) - OS Command Injection in Totolink A7100RU routers. Remotely exploitable via /cgi-bin/cstecgi[.]cgi. Public exploit available. Patch immediately! #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/iopvaQ2wqr

    Post summary

    The tweet alerts to a critical OS command injection vulnerability in Totolink A7100RU routers, states a public exploit is available, and urges immediate patching.

    0000040
    10 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6029: CRITICAL] Critical cyber security alert: Vulnerability identified in Totolink A7100RU! Immediate action needed against remote OS command injection exploit via setVpnAccountCfg function.#cve,CVE-2026-6029,#cybersecurity https://cvefind.com/CVE-2026-6029

    Post summary

    The tweet alerts about CVE‑2026‑6029 in Totolink A7100RU, describing a remote OS command injection via setVpnAccountCfg. No PoC, exploit code, or patch information is provided.

    0000062
    619 followersView on X

Explore more