CVE-2026-6155 is an OS command injection vulnerability in Totolik A7100RU router firmware version 7.4cu.2313, specifically within the setWanCfg function of the CGI handler component. An attacker can manipulate the pppoeServiceName parameter to inject and execute arbitrary operating system commands on the affected device. This vulnerability carries a critical CVSS score of 9.8, indicating severe risk with high impact across confidentiality, integrity, and availability. The vulnerability presents a network-based attack vector requiring no authentication or user interaction, making it trivially exploitable by remote threat actors. With low attack complexity and universal scope, any unauthenticated attacker on the network can potentially gain full system control of affected routers. Public exploit code has been released, significantly lowering the barrier to entry for exploitation. While the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and community attention remains relatively low as indicated by its inactive hot list status, the availability of public exploits combined with the critical severity rating presents a substantial risk to organizations operating Totolik A7100RU devices. Immediate patching or device replacement should be prioritized for affected deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Totolink | A7100RU | 7.4cu.2313CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.