Executive brief
A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and local networking. An attacker can remotely take full control of the router by sending a specially crafted request to its web management interface. This could lead to the interception of network traffic, unauthorized access to the local network, or a complete disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setDiagnosisCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability is located in the 'sub_423CC8' function, which fails to properly sanitize the 'ip' parameter before passing it to 'snprintf' and subsequently executing it via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted JSON POST request containing shell metacharacters (e.g., backticks) in the 'ip' field. Successful exploitation allows for arbitrary command execution with the privileges of the web server. A public proof-of-concept (PoC) demonstrating the creation of a file via command injection is available.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-24: disclosed: Initial disclosure and NVD publication