Junglewise Threat Intelligence

CVE-2026-5677: Totolink A7100RU command injection in cstecgi.cgi

CVE-2026-5677 · Severity: high · CVSS 7.3 · Published 2026-04-06

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely send a specially crafted request to the router to take control of the device. This could allow an unauthorized user to intercept network traffic, disrupt internet service, or use the router as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router firmware version 7.4cu.2313_b20191024. The flaw is located within the CsteSystem function in the /cgi-bin/cstecgi.cgi binary. The application fails to properly sanitize the 'resetFlags' parameter before passing it to a snprintf call, which is subsequently executed via execv(). A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands with the privileges of the web server. A public proof-of-concept (PoC) demonstrating the use of wget for command execution has been released.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-06: disclosed
  • 2026-04-06: advisory

References

Related threats