Executive brief
A security vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely send a specially crafted request to the router to take complete control of the device. This could allow an unauthorized user to monitor network traffic, disrupt internet service, or use the router as a foothold to attack other devices on the local network.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The flaw is located in the setTelnetCfg function, specifically involving the sub_4238D0 function which fails to sanitize the 'telnet_enabled' parameter. This user-provided value is passed to Uci_Set_Str and eventually executed via execv() in the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary system commands. A public exploit (PoC) has been released.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-10: disclosed: Initial vulnerability disclosure and CVE assignment