Junglewise Threat Intelligence

CVE-2026-5678: Totolink A7100RU OS command injection in cstecgi.cgi

CVE-2026-5678 · Severity: high · CVSS 7.3 · Published 2026-04-06

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

The Totolink A7100RU router, a device used for home and small office networking, contains a security flaw that allows unauthorized remote users to take control of the device. By sending a specially crafted request to the router's management interface, an attacker can execute system-level commands. This could lead to a complete compromise of the network traffic, unauthorized access to connected devices, or a total service outage.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The vulnerability is located in the setScheduleCfg function (specifically sub_42E7D8), which fails to properly sanitize the user-provided 'mode' parameter. This parameter is passed to Uci_Set_Str and subsequently formatted into a command string via snprintf before being executed by execv() through the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'mode' field to achieve arbitrary code execution. A public proof-of-concept (PoC) demonstrating the use of wget for command execution has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-06: disclosed
  • 2026-04-06: advisory

References

Related threats