Junglewise Threat Intelligence

CVE-2026-9387: Totolink A8000RU command injection in setUpgradeFW

CVE-2026-9387 · Severity: critical · CVSS 9.8 · Published 2026-05-24

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

A critical security vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take full control of the router by sending a specially crafted request to its web management interface. This could allow an unauthorized user to intercept network traffic, disrupt internet service, or use the device as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A8000RU firmware version 7.1cu.643_b20200521. The flaw is located within the 'setUpgradeFW' function of the '/cgi-bin/cstecgi.cgi' component. The application fails to properly sanitize the 'resetFlags' argument before passing it to 'snprintf' and subsequently executing it via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'resetFlags' parameter. Successful exploitation allows for arbitrary command execution on the underlying Linux operating system. A public exploit (PoC) has been released.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-05-24: disclosed: Vulnerability details and PoC published by researcher.
  • 2026-05-24: advisory: CVE-2026-9387 published.

References

Related threats