Orizon[verified]@OrizonCyberPatch
A critical CVE‑2026‑6139 affecting Totolink A7100RU has been disclosed with a CVSS of 9.8/10, and a patch is now available.
PurpleOps[verified]@PurpleOps_ioPatch
Multiple Totolink A7100RU firmware variants suffer from OS command injection via the CGI handler; exploits have been published and vendors recommend immediate patching or mitigations.
CVEFind.com@CveFindComExploit
An alert reports a critical CVE-2026‑6139 affecting Totolink routers that enables remote OS command injection, with an exploit disclosed but no evidence of active exploitation or patches.
0day Signal@0dayPublishingPoC
The tweet announces CVE-2026-6139, explaining that attackers can inject OS commands through the FileName parameter during OpenVPN cert uploads on Totolink routers, with a public exploit referenced.
CVEarity@CVEarityDisclosure
The tweet announces a newly identified CVE (2026‑6139) with a high severity score and no further technical or mitigation details.
CVE@CVEnewDisclosure
A new vulnerability (CVE-2026-6139) was reported in the Totolink A7100RU router, affecting the UploadOpenVpnCert function in cgi-bin/cstecgi.cgi, with no PoC, patch, or active exploitation mentioned.