Executive brief
The Totolink A7100RU, a wireless router used for home and business networking, contains a security flaw in its web management interface. An attacker can exploit this vulnerability to take control of the device by sending a specially crafted network request. This could lead to unauthorized access to the network, interception of data, or a complete disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router firmware version 7.4cu.2313_b20191024. The flaw is located within the 'setNtpCfg' function of the '/cgi-bin/cstecgi.cgi' binary. Specifically, the 'tz' (timezone) parameter is passed to the 'Uci_Set_Str' function and subsequently processed by 'CsteSystem' using 'snprintf' without adequate sanitization. This allows a remote, unauthenticated attacker to inject shell commands (e.g., using backticks) that are eventually executed by 'execv()'. A public Proof of Concept (PoC) demonstrates that an attacker can trigger outbound network connections or execute arbitrary system commands via a crafted POST request.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-06: disclosed
- 2026-04-06: advisory