Junglewise Threat Intelligence

CVE-2026-5689: Totolink A7100RU command injection in setNtpCfg

CVE-2026-5689 · Severity: high · CVSS 7.3 · Published 2026-04-06

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

The Totolink A7100RU, a wireless router used for home and business networking, contains a security flaw in its web management interface. An attacker can exploit this vulnerability to take control of the device by sending a specially crafted network request. This could lead to unauthorized access to the network, interception of data, or a complete disruption of internet services.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router firmware version 7.4cu.2313_b20191024. The flaw is located within the 'setNtpCfg' function of the '/cgi-bin/cstecgi.cgi' binary. Specifically, the 'tz' (timezone) parameter is passed to the 'Uci_Set_Str' function and subsequently processed by 'CsteSystem' using 'snprintf' without adequate sanitization. This allows a remote, unauthenticated attacker to inject shell commands (e.g., using backticks) that are eventually executed by 'execv()'. A public Proof of Concept (PoC) demonstrates that an attacker can trigger outbound network connections or execute arbitrary system commands via a crafted POST request.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-06: disclosed
  • 2026-04-06: advisory

References

Related threats