Executive brief
A security vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted web request. This could allow an unauthorized person to monitor network traffic, disrupt internet service, or use the device as a foothold to attack other systems on the local network.
Technical details
An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The issue resides in the setPasswordCfg function (sub_42E100), which fails to properly sanitize the 'admpass' parameter before passing it to the Uci_Set_Str function. The value is eventually processed by snprintf and executed via execv() in the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the JSON payload, leading to arbitrary command execution with root privileges. Public exploit code (PoC) is available.
Affected products
- Totolink A7100RU 7.4cu.2313_b20191024
Timeline
- 2026-04-13: disclosed: Vulnerability disclosed via VulDB and GitHub PoC
- 2026-04-13: advisory: CVE-2026-6195 published