Junglewise Threat Intelligence

CVE-2026-9385: Totolink A8000RU command injection in setTracerouteCfg

CVE-2026-9385 · Severity: critical · CVSS 9.8 · Published 2026-05-24

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and local networking. An attacker can remotely take full control of the router by sending a specially crafted request to its web management interface. This could lead to the interception of network traffic, unauthorized access to the local network, or a complete shutdown of internet services.

Technical details

An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setTracerouteCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability stems from improper neutralization of the 'command' argument, which is passed to 'snprintf' and subsequently executed via 'execv' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the JSON payload. Successful exploitation grants the attacker full root-level command execution on the underlying Linux operating system. Public exploit code (PoC) has been disclosed.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-05-24: disclosed: Vulnerability disclosed and CVE assigned via VulDB
  • 2026-05-24: advisory: NVD published the vulnerability record

References

Related threats