CVE-2026-6112General

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-04-12); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-04-12: 5Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-15: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-12: 4Technical Details · 2026-04-13: 1Technical Details · 2026-04-15: 104-1204-1304-1404-15
Signal classification4 categories
General
450.0%
Disclosure
225.0%
Patch
112.5%
PoC
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-125
Disclosure1General3Patch1
2026-04-131
Disclosure1
2026-04-141
General1
2026-04-151
PoC1
Full discourse8 posts
  • z3n@zench4n
    General

    New vulnerabilities in Totolink A7100RU (CVE-2026-6112/6113) highlight the persistent risk of unpatched edge devices. If you are running legacy firmware on these routers, you are essentially leaving a wide-open door for lateral movement within your network.

    Post summary

    The post warns about new CVEs in Totolink routers, noting the risk of legacy firmware but providing no technical details, PoC, or mitigation information.

    1000012
    1.5K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6112 — CVSS 9.8/10 ██████████ A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/JkOoqfiSxy

    Post summary

    A critical vulnerability (CVE-2026-6112) in Totolink A7100RU has been disclosed with CVSS 9.8/10, and a patch is now available; no PoC or exploitation details are provided.

    1000043
    22 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6112: Totolink A7100RU CGI cstecgi.cgi ... Remote command injection via maxRtrAdvInterval parameter in Totolink A7100RU's setRadvdCfg function - public exploit ava... https://zerodaysignal.com/vulnerability/CVE-2026-6112 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces CVE‑2026‑6112, detailing a remote command injection in Totolink A7100RU via the maxRtrAdvInterval parameter, and indicates a public PoC is available through the provided link.

    0000052
    218 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: Totolink CGI Handler Risks (CVSS 9.8-9.8) Affected: Totolink A7100RU; CF Image Hosting Script Internet-facing exposure dominates as remote CGI vulnerabilities enable command execution and data exposure. • CVE-2026-6112 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setRadvdCfg allows manipulation of maxRtrAdvInterval to enable OS command injection; remote exploitation possible. • CVE-2026-6113 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setTtyServiceCfg enables manipulation of ttyEnable causing OS command injection; remote exploitation possible. • CVE-2026-6114 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setNetworkCfg manipulation of proto leads to OS command injection; remote exploitation possible. • CVE-2019-25709 (CVSS 9.8) CF Image Hosting Script 1.6.5; Unauthenticated attackers can download and decode the application database by accessing imgdb.db in upload/data, exposing delete IDs that enable mass deletion of pictures. Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces several high‑CVSS Totolink and CF Image Hosting Script vulnerabilities, outlines technical details and remediation steps, but does not mention active exploitation or a proof of concept.

    0000042
    98 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6112 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6112 #CVE-2026-6112 #CVE #Critical #CyberSecurity #InfoSec https://t.co/5sCvaRtqJv

    Post summary

    A brief tweet announces CVE-2026-6112 with a severity of 9.8 and declares it critical, but offers no specific technical or exploitation details.

    0000030
    125 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-6112 | CVSS 9.8 🔴 CVE-2026-6113 | CVSS 9.8 🔴 CVE-2026-6114 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    A short bulletin listing three high‑CVSS CVEs and a link to a page, but lacking deeper technical or operational context.

    00000105
    5.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6112 Remote Command Injection in Totolik A7100RU 7.4cu.2313_b20191024 CGI Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6112

    Post summary

    The entry identifies a remote command injection vulnerability in a Totolik device but provides no proof of exploitation, mitigation, or real‑world attack evidence.

    0000048
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6112: CRITICAL] Critical vulnerability found in Totolink A7100RU 7.4cu.2313_b20191024 allows remote OS command injection via manipulation of maxRtrAdvInterval argument in setRadvdCfg function of /cgi...#cve,CVE-2026-6112,#cybersecurity https://cvefind.com/CVE-2026-6112

    Post summary

    An initial disclosure of a critical OS command injection flaw in Totolink A7100RU firmware has surfaced, detailing how manipulating the maxRtrAdvInterval argument enables remote exploitation.

    0000046
    620 followersView on X

Explore more