Executive brief
A security vulnerability exists in the Totolink A7100RU wireless router that allows an attacker to take complete control of the device. By sending a specially crafted request to the router's firmware update function, an attacker can execute their own commands on the system. This could lead to the theft of network traffic, unauthorized access to connected devices, or a total disruption of internet services.
Technical details
An OS command injection vulnerability exists in the CGI handler (/cgi-bin/cstecgi.cgi) of the Totolink A7100RU router, specifically within the UploadFirmwareFile function. The vulnerability is caused by improper sanitization of the 'FileName' (or 'Filename') parameter. User-provided input is passed to snprintf and subsequently executed via execv() through the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted JSON POST request containing shell metacharacters (e.g., backticks) in the filename field to achieve arbitrary code execution with root privileges. A public exploit (PoC) demonstrating the use of wget for command execution has been disclosed.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-13: advisory: NVD publication date
- 2026-04-12: disclosed: Initial disclosure via VulDB and GitHub PoC