Executive brief
A vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take full control of the router by sending a specially crafted request to its management interface. This could lead to the interception of network traffic, unauthorized access to the local network, or a complete disruption of internet services.
Technical details
An OS command injection vulnerability exists in the CGI handler (/cgi-bin/cstecgi.cgi) of the Totolink A7100RU router, specifically within the setAccessDeviceCfg function. The vulnerability stems from improper sanitization of the 'mac' parameter, which is concatenated into a system command string using strcat and snprintf before being executed via execv() in the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the 'mac' field. Successful exploitation results in arbitrary command execution with the privileges of the web service, typically root on embedded devices. Public exploit code (PoC) is available.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-13: advisory: NVD publication date