Junglewise Threat Intelligence

CVE-2026-5688: Totolink A7100RU OS command injection in setDdnsCfg

CVE-2026-5688 · Severity: high · CVSS 7.3 · Published 2026-04-06

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A7100RU wireless router, a device used to provide home and business internet connectivity. An attacker can remotely send a specially crafted request to the router's management interface to take control of the device. This could allow an unauthorized user to disrupt internet service, monitor network traffic, or use the router as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router firmware version 7.4cu.2313_b20191024. The flaw is located within the 'setDdnsCfg' function of the '/cgi-bin/cstecgi.cgi' binary. The application fails to properly sanitize the 'provider' parameter before passing it to the 'CsteSystem' function, which eventually executes the input via 'execv()'. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the JSON payload. Successful exploitation allows for arbitrary command execution with the privileges of the web server. A public PoC demonstrating the use of 'wget' for command execution has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-06: disclosed: Initial public disclosure via VulDB and GitHub PoC
  • 2026-04-06: advisory: CVE-2026-5688 published

References

Related threats