Executive brief
A security vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and network management. An attacker can exploit this flaw to take complete control of the router by executing unauthorized system commands. This could lead to the interception of network traffic, unauthorized access to connected devices, or a total disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setFirewallType' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability is caused by improper neutralization of the 'firewallType' argument, which is passed from the web management interface to the 'Uci_Set_Str' function and eventually executed via 'execv()' in 'CsteSystem'. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary OS commands with elevated privileges. A public exploit (PoC) has been disclosed.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-25: disclosed: Vulnerability disclosed and CVE assigned