Executive brief
The Totolink A8000RU router, a device used for wireless networking, contains a critical security flaw in its web management interface. An attacker can remotely send a specially crafted request to the device to take full control of the operating system. This could lead to the theft of sensitive data, interception of network traffic, or complete disruption of the internet service.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setL2tpServerCfg' function of the /cgi-bin/cstecgi.cgi component. The vulnerability stems from improper neutralization of the 'enable' parameter, which is passed to the 'Uci_Set_Str' function and subsequently processed by 'CsteSystem' using 'snprintf' before being executed via 'execv()'. A remote, unauthenticated attacker can exploit this by sending a crafted JSON payload via a POST request to execute arbitrary shell commands with the privileges of the web server. A public exploit (PoC) has been released demonstrating the creation of files on the local filesystem.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-25: disclosed: Vulnerability reported via VulDB and NVD
- 2026-05-25: advisory: CVE-2026-9436 published