CVE-2026-6132Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-13)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-12: 2Mentions · 2026-04-13: 3PoC Mentioned / Linked · 2026-04-12: 1PoC Mentioned / Linked · 2026-04-13: 1Patch / Workaround · 2026-04-13: 2Technical Details · 2026-04-12: 2Technical Details · 2026-04-13: 304-1204-13
Signal classification4 categories
Disclosure
240.0%
Exploit
120.0%
PoC
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-122
Exploit1PoC1
2026-04-133
Disclosure2Patch1
Full discourse5 posts
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-6132 — CVSS 9.8/10 ██████████ A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/YQu9QM8VfK

    Post summary

    A critical vulnerability (CVE-2026-6132) was discovered in Totolink A7100RU firmware, and a patch has been issued.

    1000045
    22 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6132 A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCfg of the file /cgi-bin/cstecgi.cgi of the compon… https://www.cve.org/CVERecord?id=CVE-2026-6132

    Post summary

    The post announces a vulnerability in the Totolink A7100RU router, pointing to the setLedCfg function in /cgi-bin/cstecgi.cgi, with no PoC, exploit, patch, or active exploitation details.

    0000096
    57.1K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    ```json { "x": "🚨 CRITICAL: CVE-2026-6132 (CVSS 9.8)\nTotolink A7100RU router vulnerable to remote OS command injection via setLedCfg function. Exploit publicly available. No auth required.\nPatch immediately or isolate affected devices.\n#CVE #Vulnerability #PatchNow #ThreatIntel", "linkedin": "🚨 CRITICAL VULNERABILITY ALERT\n\nCVE-2026-6132 | CVSS 9.8 | Remote OS Command Injection\n\nAFFECTED PRODUCT:\n• Totolink A7100RU Router\n• Version: 7.4cu.2313_b20191024\n• Component: CGI Handler (/cgi-bin/cstecgi[.]cgi)\n\nTHREAT DETAILS:\n• Vulnerability in setLedCfg function allows unauthenticated remote OS command injection\n• Attack vector: Network (AV:N)\n• No privileges required (PR:N)\n• No user interaction needed (UI:N)\n• Exploit code publicly disclosed and available\n• CWE-77 (Command Injection), CWE-78 (OS Command Injection)\n\nIMPACT:\n• Complete system compromise possible\n• High confidentiality, integrity, and availability impact\n• Remote attackers can execute arbitrary OS commands\n\nRECOMMENDED ACTIONS:\n• Apply vendor patches immediately if available\n• Isolate affected devices from internet exposure\n• Monitor for suspicious CGI requests to /cgi-bin/cstecgi[.]cgi\n• Implement network segmentation for IoT devices\n• Review logs for exploitation attempts targeting setLedCfg parameter\n\nSOC teams should prioritize detection and remediation given the critical severity and public exploit availability.\n\n#CVE #Vulnerability #PatchNow #ThreatIntel #DFIR #CyberSecurity", "reddit": "**CRITICAL VULNERABILITY: CVE-2026-6132 - Totolink A7100RU Remote OS Command Injection**\n\n**CVSS Score: 9.8 (CRITICAL)**\n\nVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n\n---\n\n**EXECUTIVE SUMMARY**\n\nA critical OS command injection vulnerability has been identified in Totolink A7100RU routers running firmware version 7.4cu.2313_b20191024. The vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands through the CGI handler. Public exploit code is available, significantly increasing the risk of active exploitation.\n\n---\n\n**AFFECTED PRODUCTS**\n\n- Product: Totolink A7100RU Router\n- Affected Version: 7.4cu.2313_b20191024\n- Vulnerable Component: CGI Handler\n- Vulnerable File: /cgi-bin/cstecgi[.]cgi\n- Vulnerable Function: setLedCfg\n\n---\n\n**TECHNICAL DETAILS**\n\nThe vulnerability exists in the setLedCfg function within the CGI handler component. Improper input validation of the \"enable\" parameter allows attackers to inject malicious OS commands that are executed with the privileges of the web server process.\n\n**CWE Classifications:**\n- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')\n- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\n\n**Attack Requirements:**\n- Network access to the device (local or internet-facing)\n- No authentication required\n- No user interaction needed\n- Low attack complexity\n\n**Attack Vector:**\nAttackers can craft malicious HTTP requests to the /cgi-bin/cstecgi[.]cgi endpoint, manipulating the \"enable\" parameter passed to the setLedCfg function to inject arbitrary OS commands.\n\n---\n\n**IMPACT ASSESSMENT**\n\n- **Confidentiality Impact: HIGH** - Complete access to device data and potentially network traffic\n- **Integrity Impact: HIGH** - Full system compromise, ability to modify configurations and firmware\n- **Availability Impact: HIGH** - Potential for device bricking or denial of service\n\nSuccessful exploitation enables attackers to:\n- Execute arbitrary commands with elevated privileges\n- Establish persistent backdoors\n- Pivot to internal network segments\n- Exfiltrate sensitive data including network credentials\n- Modify router configurations including DNS settings\n- Deploy additional malware or botnet agents\n\n---\n\n**EXPLOITATION STATUS**\n\nPublic exploit code has been disclosed and is available.

    Post summary

    CVE‑2026‑6132 is a critical remote OS command injection vulnerability on Totolink A7100RU routers; public exploit code exists and patching or isolation is urgently recommended.

    0000053
    25 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-6132: CRITICAL] Vulnerability in Totolink A7100RU 7.4cu.2313_b20191024 allows remote OS command injection via the setLedCfg function in /cgi-bin/cstecgi.cgi. Exploit disclosed publicly for remote att...#cve,CVE-2026-6132,#cybersecurity https://cvefind.com/CVE-2026-6132

    Post summary

    CVE‑2026‑6132 is a critical remote OS command‑injection flaw in Totolink A7100RU routers, with an exploit reportedly disclosed publicly but no patch or PoC details shared.

    0000051
    620 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6132: Totolink A7100R... Unauthenticated RCE via LED config parameter in Totolink routers - public exploit available for 9.3 CVSS nightmare. #RCE #RouterPwn #0day. https://zerodaysignal.com/vulnerability/CVE-2026-6132 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces a new Totolink router RCE vulnerability (CVE-2026-6132) with a public exploit available, but no active exploitation or patch information is provided.

    00000106
    217 followersView on X

Explore more