Junglewise Threat Intelligence

CVE-2026-6140: Totolink A7100RU command injection in UploadFirmwareFile

CVE-2026-6140 · Severity: critical · CVSS 9.8 · Published 2026-04-13

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A7100RU wireless router that allows an attacker to take complete control of the device. By sending a specially crafted request to the router's firmware update function, an attacker can execute their own commands on the system. This could lead to the theft of network traffic, unauthorized access to connected devices, or a total disruption of internet services.

Technical details

An OS command injection vulnerability exists in the CGI handler (/cgi-bin/cstecgi.cgi) of the Totolink A7100RU router, specifically within the UploadFirmwareFile function. The vulnerability is caused by improper sanitization of the 'FileName' (or 'Filename') parameter. User-provided input is passed to snprintf and subsequently executed via execv() through the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted JSON POST request containing shell metacharacters (e.g., backticks) in the filename field to achieve arbitrary code execution with root privileges. A public exploit (PoC) demonstrating the use of wget for command execution has been disclosed.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-13: advisory: NVD publication date
  • 2026-04-12: disclosed: Initial disclosure via VulDB and GitHub PoC

References