Junglewise Threat Intelligence

CVE-2026-9436: Totolink A8000RU command injection in setL2tpServerCfg

CVE-2026-9436 · Severity: critical · CVSS 9.8 · Published 2026-05-25

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

The Totolink A8000RU router, a device used for wireless networking, contains a critical security flaw in its web management interface. An attacker can remotely send a specially crafted request to the device to take full control of the operating system. This could lead to the theft of sensitive data, interception of network traffic, or complete disruption of the internet service.

Technical details

An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setL2tpServerCfg' function of the /cgi-bin/cstecgi.cgi component. The vulnerability stems from improper neutralization of the 'enable' parameter, which is passed to the 'Uci_Set_Str' function and subsequently processed by 'CsteSystem' using 'snprintf' before being executed via 'execv()'. A remote, unauthenticated attacker can exploit this by sending a crafted JSON payload via a POST request to execute arbitrary shell commands with the privileges of the web server. A public exploit (PoC) has been released demonstrating the creation of files on the local filesystem.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-05-25: disclosed: Vulnerability reported via VulDB and NVD
  • 2026-05-25: advisory: CVE-2026-9436 published

References

Related threats