Executive brief
A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and manage local networks. An attacker can exploit this flaw to take complete control of the router by executing unauthorized system commands. This could lead to the interception of network traffic, theft of sensitive data, or a total disruption of internet services for the home or office.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. The flaw is located within the setLanguageCfg function in the /cgi-bin/cstecgi.cgi component of the Web Management Interface. The application fails to properly sanitize the 'lang' parameter before passing it to a system execution function (CsteSystem/execv). A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request containing shell metacharacters in the 'lang' argument. Successful exploitation allows for arbitrary command execution with the privileges of the web server. A public exploit (PoC) is available.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-24: disclosed: Initial disclosure via VulDB and NVD
- 2026-05-24: advisory