Executive brief
The Totolink A7100RU, a wireless router used for home and office networking, contains a critical security flaw in its web management interface. An attacker can remotely send a specially crafted request to the device to take complete control over the operating system. This could lead to the theft of network traffic, unauthorized access to connected devices, or the use of the router in a botnet.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU firmware version 7.4cu.2313 within the /cgi-bin/cstecgi.cgi component. The root cause is improper neutralization of special elements in the 'pppoeServiceName' argument processed by the 'setWanCfg' function. Specifically, the user-provided string is passed through Uci_Set_Str_By_Idx and eventually formatted into a system command string via snprintf before being executed by execv() via the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the JSON payload. Successful exploitation allows for arbitrary command execution on the underlying Linux operating system. Public exploit code (PoC) is available.
Affected products
- Totolink A7100RU 7.4cu.2313
Timeline
- 2026-04-13: disclosed: Vulnerability details and PoC published via GitHub and VulDB.
- 2026-04-13: advisory: CVE-2026-6155 assigned and published.