CVE-2026-6116Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-12)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-11: 1Mentions · 2026-04-12: 2Technical Details · 2026-04-12: 204-1104-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-111
Disclosure1
2026-04-122
Disclosure1General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6116 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6116 #CVE-2026-6116 #CVE #Critical #CyberSecurity #InfoSec https://t.co/mznUC80oKs

    Post summary

    The tweet announces CVE-2026-6116 with a high severity rating and indicates it affects multiple products, but it provides no evidence of PoC, exploit code, or mitigation details.

    0001042
    125 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6116: CRITICAL] ⚠️ Vulnerability alert: Totolink A7100RU 7.4cu.2313_b20191024 is vulnerable to OS command injection via CGI Handler component, allowing remote exploitation. Stay vigilant!#cve,CVE-2026-6116,#cybersecurity https://cvefind.com/CVE-2026-6116

    Post summary

    The post announces that Totolink A7100RU firmware is vulnerable to OS command injection, enabling remote exploitation, but does not provide a PoC, patch, or evidence of active attacks.

    0000052
    620 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Totolink A7100RU (CVE-2026-6116) https://vuldb.com/vuln/356976

    Post summary

    A new critical vulnerability (CVE-2026-6116) has been announced for the Totolink A7100RU, with a reference to a database entry but lacking detailed technical or mitigation information.

    0000069
    2.1K followersView on X

Explore more