Executive brief
A vulnerability in the TOTOLINK A7000R wireless router allows an unauthorized person to bypass the login screen and gain administrative access to the device. By sending a specially crafted web request, an attacker can take full control of the router without needing a password. This could lead to the interception of internet traffic, unauthorized changes to network settings, or a complete disruption of service.
Technical details
An authentication bypass vulnerability (CWE-288) exists in the TOTOLINK A7000R router running firmware version 9.1.0u.6115_B20201022. The flaw is located within the 'formLoginAuth.htm' component, where the device fails to properly validate authentication requests. A remote, unauthenticated attacker can exploit this by sending a specifically crafted HTTP request to the vulnerable endpoint, effectively bypassing the login mechanism. Successful exploitation grants the attacker full administrative privileges over the device's web management interface. While a newer firmware version (V9.1.0u.6268_B20220504) is listed on the manufacturer's site, users should verify if it addresses this specific flaw.
Affected products
- TOTOLINK A7000R Firmware 9.1.0u.6115_B20201022
Timeline
- 2025-08-12: disclosed: Initial researcher disclosure on GitHub
- 2025-08-13: advisory: NVD publication date