Executive brief
The Totolink A7100RU router, a device used for home and small office networking, contains a security flaw that allows unauthorized remote users to take control of the device. By sending a specially crafted request to the router's management interface, an attacker can execute system-level commands. This could lead to a complete compromise of the network traffic, unauthorized access to connected devices, or a total service outage.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The vulnerability is located in the setScheduleCfg function (specifically sub_42E7D8), which fails to properly sanitize the user-provided 'mode' parameter. This parameter is passed to Uci_Set_Str and subsequently formatted into a command string via snprintf before being executed by execv() through the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'mode' field to achieve arbitrary code execution. A public proof-of-concept (PoC) demonstrating the use of wget for command execution has been disclosed.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-06: disclosed
- 2026-04-06: advisory