Junglewise Threat Intelligence

CVE-2026-6195: Totolink A7100RU command injection in setPasswordCfg

CVE-2026-6195 · Severity: critical · CVSS 9.8 · Published 2026-04-13

Technologies: TOTOLINK A7100ru. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink A7100RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted web request. This could allow an unauthorized person to monitor network traffic, disrupt internet service, or use the device as a foothold to attack other systems on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A7100RU router (firmware version 7.4cu.2313_b20191024) within the /cgi-bin/cstecgi.cgi component. The issue resides in the setPasswordCfg function (sub_42E100), which fails to properly sanitize the 'admpass' parameter before passing it to the Uci_Set_Str function. The value is eventually processed by snprintf and executed via execv() in the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the JSON payload, leading to arbitrary command execution with root privileges. Public exploit code (PoC) is available.

Affected products

  • Totolink A7100RU 7.4cu.2313_b20191024

Timeline

  • 2026-04-13: disclosed: Vulnerability disclosed via VulDB and GitHub PoC
  • 2026-04-13: advisory: CVE-2026-6195 published

References