Executive brief
A vulnerability exists in the Totolink A7100RU wireless router that allows an attacker to take complete control of the device remotely. By sending a specially crafted request to the router's management interface, an unauthorized user can execute system-level commands. This could lead to the interception of internet traffic, theft of sensitive data, or the use of the router as a foothold for further attacks on the internal network.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the 'setSyslogCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability stems from improper neutralization of the 'enable' parameter. The CGI handler passes this user-supplied value to the 'Uci_Set_Str' function and subsequently to 'CsteSystem', where it is executed via 'execv()' without sufficient sanitization. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters to achieve arbitrary code execution with system privileges. A public exploit (PoC) has been disclosed.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-10: advisory: Initial disclosure and NVD publication