CVE-2026-6114Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument proto results in os command injection. The attack may be initiated remotely. The exploit is now public and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-12); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-12: 4Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-12: 3Technical Details · 2026-04-13: 104-1204-13
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-124
Disclosure3Patch1
2026-04-131
Patch1
Full discourse5 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6114 — CVSS 9.8/10 ██████████ A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/R9sLisny2x

    Post summary

    The tweet announces the discovery of CVE‑2026‑6114 in Totolink A7100RU firmware, highlights its critical severity, and indicates that a patch is now available.

    1000037
    22 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Totolink CGI Handler Risks (CVSS 9.8-9.8) Affected: Totolink A7100RU; CF Image Hosting Script Internet-facing exposure dominates as remote CGI vulnerabilities enable command execution and data exposure. • CVE-2026-6112 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setRadvdCfg allows manipulation of maxRtrAdvInterval to enable OS command injection; remote exploitation possible. • CVE-2026-6113 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setTtyServiceCfg enables manipulation of ttyEnable causing OS command injection; remote exploitation possible. • CVE-2026-6114 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setNetworkCfg manipulation of proto leads to OS command injection; remote exploitation possible. • CVE-2019-25709 (CVSS 9.8) CF Image Hosting Script 1.6.5; Unauthenticated attackers can download and decode the application database by accessing imgdb.db in upload/data, exposing delete IDs that enable mass deletion of pictures. Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The tweet provides detailed technical information about multiple high‑severity vulnerabilities and emphasizes the need for immediate patching or mitigation.

    0000042
    98 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6114 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6114 #CVE-2026-6114 #CVE #Critical #CyberSecurity #InfoSec https://t.co/E6gAiUxaxj

    Post summary

    The tweet announces CVE-2026-6114 with severity information and a link to NVD, but contains no proof‑of‑concept, exploit, or patch details.

    0000034
    125 followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-6112 | CVSS 9.8 🔴 CVE-2026-6113 | CVSS 9.8 🔴 CVE-2026-6114 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet announces three new high‑CVSS CVEs (2026‑6112, 2026‑6113, 2026‑6114) and provides their severity scores, but offers no further technical or exploit information.

    00000105
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6114: CRITICAL] Critical vulnerability in Totolink A7100RU router (7.4cu.2313_b20191024) allows remote attackers to execute OS commands via manipulated arguments. Stay informed on cybersecurity threats.#cve,CVE-2026-6114,#cybersecurity https://cvefind.com/CVE-2026-6114

    Post summary

    The tweet announces a critical CVE in a Totolink router that permits remote OS command execution via argument manipulation, with no details on PoC, exploit, patch, or ongoing attacks.

    0000047
    620 followersView on X

Explore more