CVE-2026-6113Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument ttyEnable leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-12); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-12: 4Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-12: 1PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-12: 3Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 104-1204-1304-14
Signal classification3 categories
Disclosure
350.0%
PoC
233.3%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-124
Disclosure2Patch1PoC1
2026-04-131
Disclosure1
2026-04-141
PoC1
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6113 — CVSS 9.8/10 ██████████ A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/1ULN5LS7fU

    Post summary

    The tweet announces CVE‑2026‑6113 as a critical vulnerability in Totolink A7100RU, provides its CVSS score, and urges users to apply a patch immediately.

    1000041
    22 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6113: Totolink A7100RU CGI cstecgi.cgi ... Remote RCE via ttyEnable parameter in cstecgi.cgi - no auth required, public exploit available, CVSS 9.3 screams instant... https://zerodaysignal.com/vulnerability/CVE-2026-6113 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A public exploit for CVE‑2026‑6113 has been released, revealing a remote code execution flaw in the ttyEnable parameter of cstecgi.cgi with no authentication required and a CVSS score of 9.3.

    0000046
    218 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: Totolink CGI Handler Risks (CVSS 9.8-9.8) Affected: Totolink A7100RU; CF Image Hosting Script Internet-facing exposure dominates as remote CGI vulnerabilities enable command execution and data exposure. • CVE-2026-6112 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setRadvdCfg allows manipulation of maxRtrAdvInterval to enable OS command injection; remote exploitation possible. • CVE-2026-6113 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setTtyServiceCfg enables manipulation of ttyEnable causing OS command injection; remote exploitation possible. • CVE-2026-6114 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setNetworkCfg manipulation of proto leads to OS command injection; remote exploitation possible. • CVE-2019-25709 (CVSS 9.8) CF Image Hosting Script 1.6.5; Unauthenticated attackers can download and decode the application database by accessing imgdb.db in upload/data, exposing delete IDs that enable mass deletion of pictures. Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post discloses multiple critical command‑injection vulnerabilities in Totolink firmware and an image hosting script, providing technical details and patch guidance.

    0000042
    98 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6113 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6113 #CVE-2026-6113 #CVE #Critical #CyberSecurity #InfoSec https://t.co/r62OgyaQQh

    Post summary

    The tweet announces a new critical vulnerability (CVE-2026-6113) with a severe CVSS score of 9.8 affecting unspecified products, but it provides no exploit code, PoC, active exploitation reports, or patch information.

    0000032
    125 followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-6112 | CVSS 9.8 🔴 CVE-2026-6113 | CVSS 9.8 🔴 CVE-2026-6114 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The message announces today’s top vulnerabilities, listing three CVEs (CVE‑2026‑6112, CVE‑2026‑6113, CVE‑2026‑6114) with high CVSS 9.8 scores and a link for further details.

    00000105
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-6113: CRITICAL] Critical security flaw in Totolink A7100RU 7.4cu.2313_b20191024 detected, allowing remote OS command injection through CGI Handler. Attack exploit publicly disclosed & actionable.#cve,CVE-2026-6113,#cybersecurity https://cvefind.com/CVE-2026-6113

    Post summary

    The post announces a critical OS command injection flaw in Totolink A7100RU routers, noting that an exploit is publicly disclosed and actionable, with a link to more details.

    0000049
    620 followersView on X

Explore more