Executive brief
A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and manage local networks. An attacker can remotely take full control of the router by sending a specially crafted request to its web management interface. This could lead to the interception of network traffic, unauthorized access to connected devices, or a complete disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router within the /cgi-bin/cstecgi.cgi component. The root cause is the improper neutralization of the 'mode' argument in the setScheduleCfg function (sub_4264F0). The user-provided 'mode' value is passed to snprintf and subsequently executed via execv() through the CsteSystem function without adequate sanitization. A remote, unauthenticated attacker can exploit this by sending a crafted POST request to execute arbitrary system commands with root privileges. A public exploit (PoC) demonstrating the creation of files via command injection is available.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-24: disclosed: Initial disclosure and CVE assignment
- 2026-05-24: advisory: NVD publication date