Junglewise Threat Intelligence

CVE-2026-5997: Totolink A7100RU command injection in setLoginPasswordCfg

CVE-2026-5997 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take full control of the router by sending a specially crafted request to the device's management interface. This could lead to the interception of network traffic, unauthorized access to connected devices, or a complete disruption of internet service.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The root cause is located in the setLoginPasswordCfg function (sub_421678), which fails to properly sanitize the 'admpass' input parameter. This value is passed to Uci_Set_Str and subsequently formatted into a system command string using snprintf before being executed via execv() in the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary system commands. A public exploit (PoC) demonstrating a wget-based callback has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-10: advisory: NVD publication date
  • 2026-04-10: disclosed: Public disclosure of the vulnerability and PoC

References