CVE-2026-6139 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 13, 2026
Totolink A7100RU - Command Injection
Overview
Totolink A7100RU 7.4cu.2313_b20191024 contains a command injection caused by manipulation of the "FileName" argument in /cgi-bin/cstecgi.cgi UploadOpenVpnCert function, letting remote attackers execute arbitrary OS commands, exploit requires no special privileges.
Severity & Score
Impact
Remote attackers can execute arbitrary OS commands, potentially leading to full system compromise.
Mitigation
Update to the latest version.
References
Social Media Activity(1 post)
📈 CVE Published in last 7 days (2026-04-13 - 2026-04-20) See more at https://secdb.nttzen.cloud/dashboard Total CVEs: 1192 Severity: - Critical: 104 - High: 477 - Medium: 485 - Low: 67 - None: 59 Status: - : 27 - Analyzed: 155 - Awaiting Analysis: 421 - Deferred: 72 - Received: 270 - Rejected: 6 - Undergoing Analysis: 241 Top CNAs: - GitHub, Inc.: 234 - Microsoft Corporation: 163 - MITRE: 116 - Wordfence: 100 - VulDB: 77 - Adobe Systems Incorporated: 53 - Chrome: 31 - N/A: 27 - Fortinet, Inc.: 27 - VulnCheck: 23 Top Affected Products: - UNKNOWN: 856 - Microsoft Windows Server 2025: 121 - Microsoft Windows 11 24h2: 118 - Microsoft Windows 11 26h1: 117 - Microsoft Windows 11 25h2: 114 - Microsoft Windows Server 2022: 114 - Microsoft Windows 11 23h2: 113 - Microsoft Windows Server 23h2: 108 - Microsoft Windows 10 21h2: 105 - Microsoft Windows 10 22h2: 105 Top EPSS Score: - CVE-2026-6158 - 2.96 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6158) - CVE-2026-27303 - 1.50 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27303) - CVE-2026-34615 - 1.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34615) - CVE-2026-6203 - 1.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6203) - CVE-2026-6349 - 0.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6349) - CVE-2026-6141 - 0.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6141) - CVE-2026-6138 - 0.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6138) - CVE-2026-6139 - 0.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6139) - CVE-2026-6140 - 0.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6140) - CVE-2026-6154 - 0.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6154)
View original postRelated Resources
Details
- CVE ID
- CVE-2026-6139
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- unconfirmed
- EPSS
- 125.4%
- Social Posts
- 1
CWE
- CWE-77
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H