CVE-2026-6131Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument command results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-12); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-12: 3Mentions · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-12: 1Patch / Workaround · 2026-04-12: 1Technical Details · 2026-04-12: 2Technical Details · 2026-04-13: 104-1204-13
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-123
Disclosure1Exploit1Patch1
2026-04-131
Disclosure1
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6131 — CVSS 9.8/10 ██████████ A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/wLNliCO7TZ

    Post summary

    A critical vulnerability, CVE‑2026‑6131, has been identified in the Totolink A7100RU router, and a patch is now available.

    1000050
    22 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6131 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of … https://www.cve.org/CVERecord?id=CVE-2026-6131

    Post summary

    The post reports the discovery of a vulnerability (CVE‑2026‑6131) in Totolink A7100RU routers, specifically affecting the setTracerouteCfg function in cgi-bin/cstecgi.cgi.

    0000090
    57.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6131: CRITICAL] Critical cyber security alert: Totolink A7100RU 7.4cu.2313_b20191024 found vulnerable to OS command injection via setTracerouteCfg function in /cgi-bin/cstecgi.cgi. Remote attack poss...#cve,CVE-2026-6131,#cybersecurity https://cvefind.com/CVE-2026-6131

    Post summary

    The post announces a critical CVE (CVE‑2026‑6131) affecting a Totolink A7100RU router, detailing an OS command injection via the setTracerouteCfg function in a CGI script, but it provides no PoC, exploit code, patch or evidence of active exploitation.

    00000254
    620 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-6131: Totolink A7100RU CGI cstecgi.cgi ... Totolink's traceroute function lets you pipe arbitrary commands straight to the shell - no auth required, public exploit... https://zerodaysignal.com/vulnerability/CVE-2026-6131 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑6131 exposes a remote command execution flaw in Totolink A7100RU’s traceroute CGI, with no authentication required. A public exploit is available on a vulnerability site, but there is no indication of active exploitation in the wild.

    0000069
    217 followersView on X

Explore more