CVE-2026-6140General

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument FileName results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-13); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-12: 1Mentions · 2026-04-13: 3Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-13: 3Technical Details · 2026-04-14: 104-1204-1304-14
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-121
General1
2026-04-133
Disclosure2General1
2026-04-141
Patch1
Full discourse5 posts
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Totolink A7100RU CGI Handler (CVSS 9.8-9.8) Affected: Totolink A7100RU 7.4cu.2313_b20191024 Internet-facing risks dominate, led by remote command injection via CGI Handler vulnerabilities; fixes and mitigations below. • CVE-2026-6138 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in function setAccessDeviceCfg of /cgi-bin/cstecgi.cgi; manipulating the mac argument triggers OS command injection; remote exploitation; exploit published. • CVE-2026-6139 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in UploadOpenVpnCert of /cgi-bin/cstecgi.cgi; FileName manipulation leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6140 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in UploadFirmwareFile of /cgi-bin/cstecgi.cgi; FileName manipulation leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6154 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in setWizardCfg of /cgi-bin/cstecgi.cgi; manipulating the wizard argument leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6155 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in setWanCfg of /cgi-bin/cstecgi.cgi; manipulating pppoeServiceName leads to OS command injection; remote exploitation; exploit published. Action • Patch/upgrade to the fixed versions called out by the vendor (or latest Totolink firmware) addressing CGI Handler vulnerabilities. • Prioritize internet-facing instances and edge appliances first. • If no fix yet, apply mitigations and reduce exposure (disable affected CGI modules or restrict access). • Add detections for exploitation patterns (process spawning, webshell/file-write paths, unusual param manipulation). • Hunt for indicators around affected services during disclosure-to-now window (logs, EDR, WAF). • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces multiple remote command injection CVEs in Totolink A7100RU, details the technical vectors, and urges immediate patching and mitigation, but does not confirm active exploitation or provide a full PoC.

    0000041
    98 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6140 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6140 #CVE-2026-6140 #CVE #Critical #CyberSecurity #InfoSec https://t.co/sX9GGxFUwt

    Post summary

    The tweet announces a new high‑severity CVE (CVE-2026-6140) with no details on exploitation, fixes, or PoC.

    0000016
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6140 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI H… https://www.cve.org/CVERecord?id=CVE-2026-6140

    Post summary

    A new CVE (CVE-2026-6140) affecting Totolink A7100RU’s CGI UploadFirmwareFile function was disclosed, with no PoC, exploit, active use, or patch discussed.

    0000072
    57.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6140: CRITICAL] Vulnerability in Totolink A7100RU 7.4cu.2313_b20191024's CGI Handler allows remote os command injection through argument manipulation in UploadFirmwareFile function.#cve,CVE-2026-6140,#cybersecurity https://cvefind.com/CVE-2026-6140

    Post summary

    The post announces a critical remote OS command injection vulnerability (CVE‑2026‑6140) in the Totolink A7100RU router’s CGI handler via the UploadFirmwareFile function, with no PoC, exploit, or patch details provided.

    0000042
    620 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Totolink A7100RU (CVE-2026-6140) https://vuldb.com/vuln/357004

    Post summary

    The post announces increased severity for CVE-2026-6140 affecting the Totolink A7100RU, but provides no further technical or exploit information.

    0000048
    2.1K followersView on X

Explore more