CVE-2026-6195Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-13); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-13: 3Mentions · 2026-04-14: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-13: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-13: 3Technical Details · 2026-04-19: 104-1304-1404-19
Signal classification4 categories
Disclosure
240.0%
Patch
120.0%
PoC
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-133
Disclosure1Patch1PoC1
2026-04-141
General1
2026-04-191
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6195 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.… https://www.cve.org/CVERecord?id=CVE-2026-6195

    Post summary

    The post announces the detection of CVE‑2026‑6195 in a Totolink router, naming the affected function but providing no further technical or exploit details.

    00010134
    57.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6195 — CVSS 9.8/10 ██████████ A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Hld7EVg4bc

    Post summary

    The tweet announces a critical CVE for a Totolink router model, highlights its severity, and urges users to apply the available patch.

    1000033
    22 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-27681 | CVSS 9.9 🔴 CVE-2026-6195 | CVSS 9.8 🔴 CVE-2026-22563 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three high‑CVSS CVEs and links to an external vulnerability aggregator website, without providing PoC, exploit code, active exploitation, or patch information.

    0000067
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6195: CRITICAL] Security alert: Vulnerability found in Totolink A7100RU 7.4cu.2313_b20191024. Exploit allows remote OS command injection via admpass argument in /cgi-bin/cstecgi.cgi. Take precautions.#cve,CVE-2026-6195,#cybersecurity https://cvefind.com/CVE-2026-6195

    Post summary

    The post announces a critical remote OS command injection flaw (CVE‑2026‑6195) in Totolink A7100RU routers, highlighting the vulnerability's technical details but offering no patch or exploit code.

    0000042
    620 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-6195: Totolin... Unauthenticated RCE via admpass parameter in setPasswordCfg - public exploit available for this SOHO router death trap. #TotolinkRCE #CVE20266195. https://zerodaysignal.com/vulnerability/CVE-2026-6195 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The message announces CVE-2026-6195 as an unauthenticated RCE in Totolink routers and notes that a public exploit is available via the provided link.

    0000070
    217 followersView on X

Explore more