Executive brief
A vulnerability in the Totolink A8000R wireless router allows unauthorized individuals to access and modify device settings without a password. This router is commonly used to provide internet connectivity in homes and small offices. An attacker could exploit this flaw to change network configurations, potentially leading to a complete takeover of the device or disruption of internet services.
Technical details
An authentication bypass vulnerability exists in the Totolink A8000R router (firmware version 5.9c.681_B20180413) within the /cgi-bin/cstecgi.cgi component. The root cause is a failure in the cstecgi.cgi binary to validate session cookies or authentication tokens, combined with a lighttpd configuration that fails to enforce authentication on POST requests. A remote, unauthenticated attacker can send specially crafted JSON POST requests to the setLanguageCfg function (or other setting functions) to modify device parameters. This can lead to unauthorized configuration changes, including WiFi settings and administrative credentials. A public exploit is available.
Affected products
- Totolink A8000R 5.9c.681_B20180413
Timeline
- 2026-04-06: disclosed: Initial disclosure via VulDB and GitHub repository.
- 2026-04-06: advisory: CVE-2026-5676 published.