CVE-2026-6112 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setRadvdCfg maxRtrAdvInterval os command injection (EUVD-2026-21700)
A vulnerability classified as critical has been found in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection.
This vulnerability is handled as CVE-2026-6112. The attack can be initiated remotely. Additionally, an exploit exists.