Executive brief
A security vulnerability exists in the Totolink A7100RU, a wireless router used for home and office networking. An attacker can remotely send specially crafted commands to the device to take full control of its operating system. This could lead to the theft of sensitive data, interception of internet traffic, or the device being used as a foothold for further attacks on the local network.
Technical details
An OS command injection vulnerability exists in the 'setWizardCfg' function within the '/cgi-bin/cstecgi.cgi' component of Totolink A7100RU firmware version 7.4cu.2313_b20191024. The vulnerability stems from improper neutralization of the 'wizard' parameter. When a user-provided value is passed to the 'Uci_Set_Str' function, it is formatted into a command string via 'snprintf' and subsequently executed by 'execv()' through the 'CsteSystem' function without adequate validation. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary OS commands. A public exploit (PoC) has been released.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-13: disclosed: Vulnerability details and PoC published via GitHub and VulDB
- 2026-04-13: advisory: NVD published the CVE record