Junglewise Threat Intelligence

CVE-2026-6026: Totolink A7100RU OS command injection in cstecgi.cgi

CVE-2026-6026 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

The Totolink A7100RU router, a device used for home and office networking, contains a critical security flaw. An attacker can remotely take full control of the router by sending a specially crafted request to its management interface. This could lead to the interception of internet traffic, unauthorized access to the local network, or a complete disruption of internet services.

Technical details

An OS command injection vulnerability exists in the 'setPortalConfWeChat' function within '/cgi-bin/cstecgi.cgi' on Totolink A7100RU routers (version 7.4cu.2313_b20191024). The vulnerability is rooted in the 'sub_423704' function, which fails to sanitize the 'enabled' (or 'enable') parameter before passing it to 'snprintf' and subsequently executing it via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted JSON POST request to the CGI handler. Successful exploitation allows for arbitrary command execution as the root user. A public proof-of-concept (PoC) demonstrating the use of backticks for command injection has been released.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-10: disclosed: Vulnerability reported via VulDB and GitHub PoC
  • 2026-04-10: advisory: NVD published the CVE record

References