Executive brief
The Totolink A7100RU router, a device used for home and office networking, contains a critical security flaw. An attacker can remotely take full control of the router by sending a specially crafted request to its management interface. This could lead to the interception of internet traffic, unauthorized access to the local network, or a complete disruption of internet services.
Technical details
An OS command injection vulnerability exists in the 'setPortalConfWeChat' function within '/cgi-bin/cstecgi.cgi' on Totolink A7100RU routers (version 7.4cu.2313_b20191024). The vulnerability is rooted in the 'sub_423704' function, which fails to sanitize the 'enabled' (or 'enable') parameter before passing it to 'snprintf' and subsequently executing it via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted JSON POST request to the CGI handler. Successful exploitation allows for arbitrary command execution as the root user. A public proof-of-concept (PoC) demonstrating the use of backticks for command injection has been released.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-10: disclosed: Vulnerability reported via VulDB and GitHub PoC
- 2026-04-10: advisory: NVD published the CVE record