Executive brief
A security vulnerability has been identified in the Totolink A8000RU wireless router. This flaw allows an attacker to remotely take control of the device by sending a specially crafted request to the router's management interface. Successful exploitation could lead to a complete compromise of the network traffic passing through the device, unauthorized access to internal data, or a total disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The flaw is located within the 'setPptpServerCfg' function in '/cgi-bin/cstecgi.cgi'. The root cause is the improper neutralization of the 'enable' argument, which is passed to the 'Uci_Set_Str' function and subsequently executed via 'execv()' through the 'CsteSystem' function in 'libcscommon.so'. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks or semicolons) in the JSON payload. This allows for arbitrary command execution on the underlying Linux operating system with high privileges. A public PoC demonstrating the creation of a file via the 'ls' command has been disclosed.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-04-28: disclosed: Vulnerability details and PoC publicly released.
- 2026-04-28: advisory: CVE-2026-7204 published.