Executive brief
A security vulnerability exists in the Totolink A7100RU router, a device used to provide wireless internet connectivity. An attacker can remotely take full control of the router by sending a specially crafted request to the device's management interface. This could lead to the interception of internet traffic, unauthorized access to the local network, or a complete shutdown of the device's services.
Technical details
An OS command injection vulnerability exists in the 'setVpnAccountCfg' function within the '/cgi-bin/cstecgi.cgi' component of Totolink A7100RU firmware version 7.4cu.2313_b20191024. The vulnerability stems from improper neutralization of the 'User' argument, which is passed to the 'Uci_Set_Str' function and subsequently executed via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the 'user' JSON field. Successful exploitation grants the attacker full system-level command execution on the underlying operating system.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-10: disclosed: Vulnerability details and PoC made public via GitHub and VulDB.
- 2026-04-10: advisory: CVE-2026-6029 published.