Junglewise Threat Intelligence

CVE-2026-6025: Totolink A7100RU command injection in setSyslogCfg

CVE-2026-6025 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink A7100RU wireless router that allows an attacker to take complete control of the device remotely. By sending a specially crafted request to the router's management interface, an unauthorized user can execute system-level commands. This could lead to the interception of internet traffic, theft of sensitive data, or the use of the router as a foothold for further attacks on the internal network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the 'setSyslogCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability stems from improper neutralization of the 'enable' parameter. The CGI handler passes this user-supplied value to the 'Uci_Set_Str' function and subsequently to 'CsteSystem', where it is executed via 'execv()' without sufficient sanitization. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters to achieve arbitrary code execution with system privileges. A public exploit (PoC) has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-10: advisory: Initial disclosure and NVD publication

References