Junglewise Threat Intelligence

CVE-2026-7204: Totolink A8000RU command injection in setPptpServerCfg

CVE-2026-7204 · Severity: critical · CVSS 9.8 · Published 2026-04-28

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

A security vulnerability has been identified in the Totolink A8000RU wireless router. This flaw allows an attacker to remotely take control of the device by sending a specially crafted request to the router's management interface. Successful exploitation could lead to a complete compromise of the network traffic passing through the device, unauthorized access to internal data, or a total disruption of internet services.

Technical details

An OS command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The flaw is located within the 'setPptpServerCfg' function in '/cgi-bin/cstecgi.cgi'. The root cause is the improper neutralization of the 'enable' argument, which is passed to the 'Uci_Set_Str' function and subsequently executed via 'execv()' through the 'CsteSystem' function in 'libcscommon.so'. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks or semicolons) in the JSON payload. This allows for arbitrary command execution on the underlying Linux operating system with high privileges. A public PoC demonstrating the creation of a file via the 'ls' command has been disclosed.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-04-28: disclosed: Vulnerability details and PoC publicly released.
  • 2026-04-28: advisory: CVE-2026-7204 published.

References

Related threats