Executive brief
A vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take full control of the router by sending a specially crafted request to the device's management interface. This could lead to the interception of network traffic, unauthorized access to connected devices, or a complete disruption of internet service.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The root cause is located in the setLoginPasswordCfg function (sub_421678), which fails to properly sanitize the 'admpass' input parameter. This value is passed to Uci_Set_Str and subsequently formatted into a system command string using snprintf before being executed via execv() in the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary system commands. A public exploit (PoC) demonstrating a wget-based callback has been disclosed.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-10: advisory: NVD publication date
- 2026-04-10: disclosed: Public disclosure of the vulnerability and PoC