A vulnerability was detected in Totolink A7100RU 7.4cu...
High severity
Unreviewed
Published
Apr 9, 2026
to the GitHub Advisory Database
•
Updated Apr 9, 2026
Description
Published by the National Vulnerability Database
Apr 9, 2026
Published to the GitHub Advisory Database
Apr 9, 2026
Last updated
Apr 9, 2026
A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument merge results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
References