Junglewise Threat Intelligence

CVE-2026-9406: Totolink A8000RU command injection in setRemoteCfg

CVE-2026-9406 · Severity: critical · CVSS 9.8 · Published 2026-05-25

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

The Totolink A8000RU router, a device used to provide wireless internet connectivity, contains a critical security flaw in its web management interface. An attacker can exploit this vulnerability to take complete control of the router by sending a specially crafted network request. This could allow an unauthorized user to intercept internet traffic, disrupt network services, or use the device as a foothold for further attacks on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setRemoteCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability stems from improper neutralization of the 'enable' argument, which is passed to the 'Uci_Set_Str' function and eventually executed via 'execv()' in the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'enable' parameter. Successful exploitation results in arbitrary command execution with the privileges of the web server. A public proof-of-concept (PoC) is available.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-05-25: advisory: NVD published the vulnerability record.

References

Related threats