CVE-2026-6156Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument Comment leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-13)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-12: 1Mentions · 2026-04-13: 3PoC Mentioned / Linked · 2026-04-13: 2Exploit Tool / Code · 2026-04-13: 1Technical Details · 2026-04-13: 304-1204-13
Signal classification4 categories
Disclosure
125.0%
Exploit
125.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-121
Disclosure1
2026-04-133
Exploit1General1PoC1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Totolink A7100RU (CVE-2026-6156) https://vuldb.com/vuln/357036

    Post summary

    A new elevated‑criticality vulnerability (CVE‑2026‑6156) in the Totolink A7100RU is announced, but the post contains minimal detail and no PoC, exploit, patch, or exploitation evidence.

    0102092
    2.2K followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6156: Totolink A7100RU CGI cstecgi.cgi ... Another Totolink router falls to trivial command injection via Comment parameter - public exploit available means mass b... https://zerodaysignal.com/vulnerability/CVE-2026-6156 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A public proof of concept for CVE-2026-6156, a trivial command injection in Totolink A7100RU routers, is available online.

    0000053
    218 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-34865 | CVSS 10.0 🔴 CVE-2026-6154 | CVSS 9.8 🔴 CVE-2026-6156 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑scoring CVEs and a link to a vulnerability page, but provides no PoC, exploit, patch, or further technical details beyond the CVSS scores.

    00000105
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-6156: CRITICAL] Security alert: Totolink A7100RU 7.4cu.2313_b20191024 is vulnerable to remote os command injection via 'setIpQosRules' function. Public exploit available, take precaution.#cve,CVE-2026-6156,#cybersecurity https://cvefind.com/CVE-2026-6156

    Post summary

    The tweet announces that CVE‑2026‑6156 in Totolink A7100RU devices is a remote OS command injection flaw with a publicly available exploit, but no patch or active exploitation is mentioned.

    0000028
    620 followersView on X

Explore more