Junglewise Threat Intelligence

CVE-2026-5692: Totolink A7100RU command injection in setGameSpeedCfg

CVE-2026-5692 · Severity: high · CVSS 7.3 · Published 2026-04-07

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

The Totolink A7100RU is a wireless router used for home and business networking. A security flaw in its web management interface allows a remote attacker to take control of the device by sending a specially crafted request. This could lead to unauthorized access to network traffic, service disruptions, or the use of the router as a foothold for further attacks on the internal network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router firmware version 7.4cu.2313_b20191024. The flaw is located within the 'setGameSpeedCfg' function in the '/cgi-bin/cstecgi.cgi' binary. The application fails to properly sanitize the 'enable' parameter before passing it to the 'Uci_Set_Str' function and subsequently to 'CsteSystem', where it is executed via 'execv()'. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'enable' field to execute arbitrary system commands with the privileges of the web server. A public proof-of-concept (PoC) demonstrating the use of 'wget' via this injection has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-07: advisory: Initial disclosure by VulDB/NVD
  • 2026-04-07: disclosed: Public PoC released on GitHub

References

Related threats