Executive brief
TOTOLINK N600R is a wireless router used to provide network connectivity in homes and small offices. A vulnerability in its web configuration interface allows an attacker to inject arbitrary commands by manipulating the NTP server parameter, potentially enabling remote code execution and complete control of the device.
Technical details
The vulnerability is a command injection flaw in the getCurrentTime function of /cgi-bin/cstecgi.cgi in TOTOLINK N600R firmware version 4.3.0cu.7647_B20210106. The ntp_server parameter is passed unsanitized to a shell command (popen), allowing an attacker to inject arbitrary OS commands. The attack is network-accessible with no authentication required. An attacker can achieve remote code execution with the privileges of the web server process, potentially gaining full device compromise. No patch information is currently available.
Affected products
- TOTOLINK N600R 4.3.0cu.7647_B20210106
Timeline
- 2026-08-25: disclosed