Executive brief
A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and manage local networks. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted request to its web management interface. This could lead to the interception of network traffic, unauthorized access to connected devices, or a total disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the /cgi-bin/cstecgi.cgi component. The vulnerability is located in the setStaticDhcpRules function, specifically due to improper neutralization of the 'enable' argument. The application uses snprintf to incorporate this user-supplied parameter into a system command string, which is subsequently executed via execv() through the CsteSystem function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands with the privileges of the web server. A public exploit (PoC) demonstrating file creation via the 'ls' command has been disclosed.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-25: advisory: NVD publication date
- 2026-05-24: disclosed: Initial disclosure by VulDB and public PoC release