CVE-2026-6139Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-13); latest day: 2
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-04-13: 4Mentions · 2026-04-14: 2PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-14: 2Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-13: 3Technical Details · 2026-04-14: 204-1304-14
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
Exploit
116.7%
PoC
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-134
Disclosure2Exploit1Patch1
2026-04-142
Patch1PoC1
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6139 — CVSS 9.8/10 ██████████ A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/f1P6Ahgl7R

    Post summary

    A critical CVE‑2026‑6139 affecting Totolink A7100RU has been disclosed with a CVSS of 9.8/10, and a patch is now available.

    1000052
    22 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-6139: CRITICAL] Alert: Cybersecurity vulnerability in Totolink A7100RU 7.4cu.2313_b20191024 discovered, enabling remote OS command injection via CGI Handler. Exploit disclosed and may be utilized. #c...#cve,CVE-2026-6139,#cybersecurity https://cvefind.com/CVE-2026-6139

    Post summary

    An alert reports a critical CVE-2026‑6139 affecting Totolink routers that enables remote OS command injection, with an exploit disclosed but no evidence of active exploitation or patches.

    0000148
    620 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6139: Totolink A7100RU CGI cstecgi.cgi ... Totolink's A7100RU router lets attackers inject OS commands through FileName parameter in OpenVPN cert uploads—public ex... https://zerodaysignal.com/vulnerability/CVE-2026-6139 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-6139, explaining that attackers can inject OS commands through the FileName parameter during OpenVPN cert uploads on Totolink routers, with a public exploit referenced.

    0000075
    218 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Totolink A7100RU CGI Handler (CVSS 9.8-9.8) Affected: Totolink A7100RU 7.4cu.2313_b20191024 Internet-facing risks dominate, led by remote command injection via CGI Handler vulnerabilities; fixes and mitigations below. • CVE-2026-6138 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in function setAccessDeviceCfg of /cgi-bin/cstecgi.cgi; manipulating the mac argument triggers OS command injection; remote exploitation; exploit published. • CVE-2026-6139 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in UploadOpenVpnCert of /cgi-bin/cstecgi.cgi; FileName manipulation leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6140 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in UploadFirmwareFile of /cgi-bin/cstecgi.cgi; FileName manipulation leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6154 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in setWizardCfg of /cgi-bin/cstecgi.cgi; manipulating the wizard argument leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6155 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in setWanCfg of /cgi-bin/cstecgi.cgi; manipulating pppoeServiceName leads to OS command injection; remote exploitation; exploit published. Action • Patch/upgrade to the fixed versions called out by the vendor (or latest Totolink firmware) addressing CGI Handler vulnerabilities. • Prioritize internet-facing instances and edge appliances first. • If no fix yet, apply mitigations and reduce exposure (disable affected CGI modules or restrict access). • Add detections for exploitation patterns (process spawning, webshell/file-write paths, unusual param manipulation). • Hunt for indicators around affected services during disclosure-to-now window (logs, EDR, WAF). • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    Multiple Totolink A7100RU firmware variants suffer from OS command injection via the CGI handler; exploits have been published and vendors recommend immediate patching or mitigations.

    0000041
    98 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6139 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6139 #CVE-2026-6139 #CVE #Critical #CyberSecurity #InfoSec https://t.co/cDYlKKEBdv

    Post summary

    The tweet announces a newly identified CVE (2026‑6139) with a high severity score and no further technical or mitigation details.

    0000019
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6139 A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component C… https://www.cve.org/CVERecord?id=CVE-2026-6139

    Post summary

    A new vulnerability (CVE-2026-6139) was reported in the Totolink A7100RU router, affecting the UploadOpenVpnCert function in cgi-bin/cstecgi.cgi, with no PoC, patch, or active exploitation mentioned.

    0000069
    57.1K followersView on X

Explore more