Executive brief
The Totolink A7100RU is a wireless router used for home and business networking. A security flaw in its web management interface allows a remote attacker to take control of the device by sending a specially crafted request. This could lead to unauthorized access to network traffic, service disruptions, or the use of the router as a foothold for further attacks on the internal network.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router firmware version 7.4cu.2313_b20191024. The flaw is located within the 'setGameSpeedCfg' function in the '/cgi-bin/cstecgi.cgi' binary. The application fails to properly sanitize the 'enable' parameter before passing it to the 'Uci_Set_Str' function and subsequently to 'CsteSystem', where it is executed via 'execv()'. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'enable' field to execute arbitrary system commands with the privileges of the web server. A public proof-of-concept (PoC) demonstrating the use of 'wget' via this injection has been disclosed.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-07: advisory: Initial disclosure by VulDB/NVD
- 2026-04-07: disclosed: Public PoC released on GitHub