CVE-2026-6168Disclosure

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. The affected element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid5g causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-13); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-12: 1Mentions · 2026-04-13: 4Mentions · 2026-04-29: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-29: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-13: 3Technical Details · 2026-04-29: 104-1204-1304-29
Signal classification4 categories
Disclosure
350.0%
General
116.7%
PoC
116.7%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-121
General1
2026-04-134
Disclosure3PoC1
2026-04-291
Patch1
Full discourse6 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-6168 (CVSS 8.8) affects TOTOLINK A7000R routers ≤9.1.0u.6115. Stack-based buffer overflow in setWiFiEasyGuestCfg. Remotely exploitable with public exploit. Patch immediately. #CVE #PatchNow https://t.co/MBjZLzkWxy

    Post summary

    The tweet announces a high‑severity CVE involving a stack buffer overflow on specific routers, notes a public exploit exists, and urges users to apply the patch immediately.

    0000035
    9 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6168 A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. The affected element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. This manipulation… https://www.cve.org/CVERecord?id=CVE-2026-6168

    Post summary

    The text announces the discovery of CVE-2026-6168 in TOTOLINK A7000R routers, identifying the affected function 'setWiFiEasyGuestCfg' in the CGI script.

    0000099
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6168 Remote Code Execution via Stack Buffer Overflow in TOTOLINK A7000R 9.1.0u.6115 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6168

    Post summary

    The post announces a new RCE vulnerability in TOTOLINK A7000R, providing a brief technical description but no exploit code, PoC, or mitigation info.

    0000036
    4.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    PoC

    🚨 HIGH: CVE-2026-6168 (CVSS 8.8) - Stack-based buffer overflow in TOTOLINK A7000R routers ≤9.1.0u.6115. Remote exploitation possible. Exploit code public. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/HEckUL97hm

    Post summary

    CVE-2026-6168 is a stack‑based buffer overflow in TOTOLINK A7000R routers with publicly available exploit code; immediate patching is advised.

    0000044
    25 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6168: HIGH] Critical vulnerability discovered in TOTOLINK A7000R up to 9.1.0u.6115 allowing remote attackers to trigger stack-based buffer overflow. Be cautious.#cve,CVE-2026-6168,#cybersecurity https://cvefind.com/CVE-2026-6168

    Post summary

    A high‑severity stack‐based buffer overflow in TOTOLINK A7000R is disclosed; no PoC, exploit, active use, or patch details are provided.

    0000052
    620 followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in TOTOLINK A7000R (CVE-2026-6168) https://vuldb.com/vuln/357056

    Post summary

    The post simply announces a new critical vulnerability (CVE-2026-6168) affecting the TOTOLINK A7000R, with no further technical, exploit, or mitigation details provided.

    0000087
    2.1K followersView on X

Explore more