Junglewise Threat Intelligence

CVE-2026-5994: Totolink A7100RU command injection in setTelnetCfg

CVE-2026-5994 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely send a specially crafted request to the router to take complete control of the device. This could allow an unauthorized user to monitor network traffic, disrupt internet service, or use the router as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The flaw is located in the setTelnetCfg function, specifically involving the sub_4238D0 function which fails to sanitize the 'telnet_enabled' parameter. This user-provided value is passed to Uci_Set_Str and eventually executed via execv() in the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary system commands. A public exploit (PoC) has been released.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-10: disclosed: Initial vulnerability disclosure and CVE assignment

References