Report: CVE-2026-6139 - Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection - Analysis

Report: CVE-2026-6139 - Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection - Analysis

CVE ID :CVE-2026-6139 Published : April 13, 2026, 12:15 a.m. | 1 hour, 8 minutes ago Description :A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
April 13, 2026
Impact: command injection