Junglewise Threat Intelligence

CVE-2026-5995: Totolink A7100RU OS command injection in cstecgi.cgi

CVE-2026-5995 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink A7100RU home router that allows an attacker to take complete control of the device. By sending a specially crafted network request, a remote attacker can execute unauthorized commands on the router's operating system. This could lead to the interception of internet traffic, theft of sensitive data, or the use of the device as a foothold for further attacks on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router within the 'setMiniuiHomeInfoShow' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability is caused by improper neutralization of the 'lan_info' argument, which is passed to 'snprintf' and subsequently executed via 'execv' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the 'lan_info' parameter. Successful exploitation results in arbitrary command execution with the privileges of the CGI handler. A public proof-of-concept (PoC) demonstrating the use of backticks for command execution is available.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-10: disclosed: Vulnerability disclosed via VulDB and NVD

References