Junglewise Threat Intelligence

CVE-2026-6113: Totolink A7100RU OS command injection in cstecgi.cgi

CVE-2026-6113 · Severity: critical · CVSS 9.8 · Published 2026-04-12

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A7100RU home router, a device used to provide wireless internet connectivity. An attacker can remotely send a specially crafted request to the router to take complete control of the device. This could allow an unauthorized user to monitor network traffic, disrupt internet service, or use the router as a foothold to attack other devices on the home network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU firmware version 7.4cu.2313_b20191024. The flaw is located within the 'setTtyServiceCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability is caused by improper neutralization of the 'ttyEnable' argument, which is passed to the 'Uci_Set_Str' function and eventually executed via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands with elevated privileges. A public exploit (PoC) has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-12: disclosed: Vulnerability and PoC publicly disclosed via GitHub and VulDB
  • 2026-04-12: advisory: CVE-2026-6113 published

References