Junglewise Threat Intelligence

CVE-2026-6028: TOTOLINK A7100RU command injection in cstecgi.cgi

CVE-2026-6028 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the TOTOLINK A7100RU, a wireless router used for home and office networking. An attacker can remotely take full control of the device by sending a specially crafted request to the router's management interface. This could lead to the interception of internet traffic, unauthorized access to the local network, or a complete disruption of internet services.

Technical details

An OS command injection vulnerability exists in the 'setPptpServerCfg' function within the '/cgi-bin/cstecgi.cgi' component of the TOTOLINK A7100RU router (firmware version 7.4cu.2313_b20191024). The root cause is the improper neutralization of the 'enable' argument, which is passed to the 'Uci_Set_Str' function and subsequently executed via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the JSON payload. Successful exploitation allows for arbitrary command execution with the privileges of the web server, typically root on such devices.

Affected products

  • TOTOLINK A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-10: disclosed: Public disclosure of the vulnerability and PoC.
  • 2026-04-10: advisory: CVE-2026-6028 published.

References