Executive brief
A vulnerability exists in the Totolink A7100RU home router that allows an attacker to take complete control of the device. By sending a specially crafted network request to the router's diagnostic settings, an unauthorized user can execute system-level commands. This could lead to the interception of internet traffic, theft of sensitive data, or the use of the device in a botnet.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the 'setDiagnosisCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability is rooted in the improper sanitization of the 'ip' parameter, which is passed to 'snprintf' and subsequently executed via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted JSON POST request containing shell metacharacters (e.g., backticks) in the 'ip' field. Successful exploitation allows for arbitrary command execution on the underlying Linux operating system. Public exploit code (PoC) has been disclosed.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-12: disclosed: Vulnerability and PoC disclosed to the public
- 2026-04-12: advisory: NVD/VulDB advisory published