Executive brief
A security vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take full control of the router by sending a specially crafted network request. This could lead to the theft of sensitive data, interception of internet traffic, or a complete shutdown of the network.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The vulnerability is located in the setNetworkCfg function (specifically sub_428414), where the 'proto' parameter is insufficiently sanitized before being passed to a system execution function. An unauthenticated remote attacker can exploit this by sending a crafted JSON POST request containing shell metacharacters in the 'proto' field. Successful exploitation allows for arbitrary command execution with the privileges of the web server, typically root on such devices. A public exploit (PoC) is available.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-12: disclosed: Vulnerability disclosed via VulDB and GitHub PoC
- 2026-04-12: advisory: CVE-2026-6114 published