Junglewise Threat Intelligence

CVE-2026-5690: Totolink A7100RU OS command injection in setRemoteCfg

CVE-2026-5690 · Severity: high · CVSS 7.3 · Published 2026-04-06

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability has been identified in the Totolink A7100RU home router. This flaw allows an attacker to remotely execute unauthorized commands on the device by sending a specially crafted web request. If exploited, an attacker could gain full control over the router, potentially leading to the interception of internet traffic, unauthorized access to the local network, or disruption of internet services.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router, specifically within the 'setRemoteCfg' function of the /cgi-bin/cstecgi.cgi component. The vulnerability stems from the improper neutralization of the 'enable' argument, which is passed to the Uci_Set_Str function and eventually executed via execv() in the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'enable' parameter. Successful exploitation allows for arbitrary command execution with the privileges of the web server. A public Proof of Concept (PoC) using wget has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-06: disclosed
  • 2026-04-06: advisory

References

Related threats