CVE-2026-6155Disclosure

MEDIUMCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument pppoeServiceName can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1Mentions · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-22: 1Exploit Tool / Code · 2026-04-22: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-22: 104-1304-1404-22
Signal classification3 categories
Disclosure
133.3%
Exploit
133.3%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-131
Disclosure1
2026-04-141
Exploit1
2026-04-221
Patch1
Full discourse3 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-6155 (CVSS 9.8) - OS Command Injection in Totolink A7100RU router. Remotely exploitable via setWanCfg function. Public exploit available. Patch immediately! #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/YlxIq7jYi2

    Post summary

    The tweet announces a critical CVE affecting Totolink routers, confirms a publicly available exploit, and urges immediate patching to mitigate the OS command injection.

    0000062
    26 followersView on X
  • PurpleOps@PurpleOps_io
    Exploit

    🚨 Critical CVEs Today: Totolink A7100RU CGI Handler (CVSS 9.8-9.8) Affected: Totolink A7100RU 7.4cu.2313_b20191024 Internet-facing risks dominate, led by remote command injection via CGI Handler vulnerabilities; fixes and mitigations below. • CVE-2026-6138 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in function setAccessDeviceCfg of /cgi-bin/cstecgi.cgi; manipulating the mac argument triggers OS command injection; remote exploitation; exploit published. • CVE-2026-6139 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in UploadOpenVpnCert of /cgi-bin/cstecgi.cgi; FileName manipulation leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6140 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in UploadFirmwareFile of /cgi-bin/cstecgi.cgi; FileName manipulation leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6154 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in setWizardCfg of /cgi-bin/cstecgi.cgi; manipulating the wizard argument leads to OS command injection; remote exploitation; exploit published. • CVE-2026-6155 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024 vulnerability in setWanCfg of /cgi-bin/cstecgi.cgi; manipulating pppoeServiceName leads to OS command injection; remote exploitation; exploit published. Action • Patch/upgrade to the fixed versions called out by the vendor (or latest Totolink firmware) addressing CGI Handler vulnerabilities. • Prioritize internet-facing instances and edge appliances first. • If no fix yet, apply mitigations and reduce exposure (disable affected CGI modules or restrict access). • Add detections for exploitation patterns (process spawning, webshell/file-write paths, unusual param manipulation). • Hunt for indicators around affected services during disclosure-to-now window (logs, EDR, WAF). • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces critical TotalLink A7100RU command injection vulnerabilities with published exploits and recommends patching or mitigation.

    0000041
    98 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6155: CRITICAL] Weakness identified in Totolink A7100RU 7.4cu.2313's CGI Handler, allows remote os command injections via pppoeServiceName parameter. Public exploit available.#cve,CVE-2026-6155,#cybersecurity https://cvefind.com/CVE-2026-6155

    Post summary

    A critical remote OS command injection flaw was identified in Totolink A7100RU firmware, and a public exploit for the vulnerability has been made available.

    0000026
    620 followersView on X

Explore more