Junglewise Threat Intelligence

CVE-2026-9405: Totolink A8000RU command injection in setGameSpeedCfg

CVE-2026-9405 · Severity: critical · CVSS 9.8 · Published 2026-05-25

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

A critical security vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and network management. An attacker can remotely take full control of the router by sending a specially crafted request to its web management interface. This could lead to the theft of sensitive data, interception of network traffic, or a complete shutdown of the device's operations.

Technical details

An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the /cgi-bin/cstecgi.cgi component. The flaw is located in the setGameSpeedCfg function, specifically within the sub_420CA8 routine, which fails to properly sanitize the 'enable' parameter. This user-provided value is passed to snprintf and subsequently executed via execv() through the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters to achieve arbitrary code execution with system privileges. A public exploit (PoC) has been released.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-05-25: advisory: NVD publication date

References

Related threats