Executive brief
A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and Wi-Fi. An attacker can remotely take full control of the router by sending a specially crafted request to the device's management interface. This could lead to the theft of sensitive data, interception of network traffic, or a complete disruption of internet services for the home or business.
Technical details
An OS command injection vulnerability exists in the 'setWiFiWpsStart' function within the '/cgi-bin/cstecgi.cgi' component of the Totolink A8000RU router (firmware version 7.1cu.643_b20200521). The root cause is improper neutralization of the 'wscDisabled' argument, which is concatenated into a system command string using 'snprintf' and subsequently executed via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the JSON payload. Successful exploitation allows for arbitrary command execution on the underlying Linux operating system. Public exploits (PoC) are available.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-04-28: advisory: Initial disclosure by VulDB/NVD
- 2026-04-28: disclosed: Public PoC released on GitHub