CVE-2026-6138Patch

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mac causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-04-13); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-13: 5Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-13: 1Patch / Workaround · 2026-04-13: 2Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-13: 5Technical Details · 2026-04-14: 104-1304-14
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
PoC
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-135
Disclosure2Patch2PoC1
2026-04-141
Patch1
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6138 — CVSS 9.8/10 ██████████ A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/OMK86g7FDY

    Post summary

    The tweet discloses a critical vulnerability in Totolink A7100RU, provides basic technical details, and indicates that a patch is available.

    1000028
    22 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6138: Tot... Unauthenticated RCE via `mac` parameter in setAccessDeviceCfg - classic router pwn with public exploit already dropped. #RouterPwn #RCE #TotolinkFail. https://zerodaysignal.com/vulnerability/CVE-2026-6138 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑6138, noting an unauthenticated RCE via the ‘mac’ parameter, and confirms that a public exploit has already been released.

    00010102
    217 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Totolink A7100RU CGI Handler (CVSS 9.8-9.8) Affected: Totolink A7100RU 7.4cu.2313_b20191024 Internet-facing risks dominate, led by remote command injection via CGI Handler vulnerabilities; fixes and mitigations below. • CVE-2026-6138 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in function setAccessDeviceCfg of /cgi-bin/cstecgi.cgi; manipulating the mac argument triggers OS command injection; remote exploitation; exploit published. • CVE-2026-6139 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in UploadOpenVpnCert of /cgi-bin/cstecgi.cgi; FileName manipulation leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6140 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in UploadFirmwareFile of /cgi-bin/cstecgi.cgi; FileName manipulation leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6154 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in setWizardCfg of /cgi-bin/cstecgi.cgi; manipulating the wizard argument leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6155 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in setWanCfg of /cgi-bin/cstecgi.cgi; manipulating pppoeServiceName leads to OS command injection; remote exploitation; exploit published. Action • Patch/upgrade to the fixed versions called out by the vendor (or latest Totolink firmware) addressing CGI Handler vulnerabilities. • Prioritize internet-facing instances and edge appliances first. • If no fix yet, apply mitigations and reduce exposure (disable affected CGI modules or restrict access). • Add detections for exploitation patterns (process spawning, webshell/file-write paths, unusual param manipulation). • Hunt for indicators around affected services during disclosure-to-now window (logs, EDR, WAF). • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post details critical OS command injection vulnerabilities in Totolink A7100RU CGI handlers, cites published exploits, and urges rapid patching and mitigation.

    0000041
    98 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6138 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6138 #CVE-2026-6138 #CVE #Critical #CyberSecurity #InfoSec https://t.co/4z8B3zJ0wc

    Post summary

    The tweet announces CVE‑2026‑6138, a critical vulnerability with a CVSS score of 9.8, but provides no PoC, exploit, or patch details.

    0000025
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6138 A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the componen… https://www.cve.org/CVERecord?id=CVE-2026-6138

    Post summary

    The description announces a flaw (CVE-2026-6138) in Totolink A7100RU affecting the setAccessDeviceCfg function within cgi-bin/cstecgi.cgi, providing basic technical details without mentioning PoC, exploit, patch, or active exploitation.

    0000070
    57.1K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-6138: CRITICAL] Critical cyber security vulnerability discovered in Totolink A7100RU 7.4cu.2313_b20191024. Remote attackers can execute OS commands via CGI Handler. Patch recommended immediately.#cve,CVE-2026-6138,#cybersecurity https://cvefind.com/CVE-2026-6138

    Post summary

    A critical vulnerability in the Totolink A7100RU router permits remote OS command execution via the CGI handler, and a patch is urgently recommended.

    0000050
    620 followersView on X

Explore more