Executive brief
The Totolink A8000RU router, a device used for home and office networking, contains a critical security flaw in its web management interface. An attacker can exploit this vulnerability to take complete control of the router by sending a specially crafted web request. This could lead to the interception of network traffic, unauthorized access to the local network, or a total disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setOpenVpnCertGenerationCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability is rooted in the 'sub_42A958' function, which fails to properly sanitize the 'servername' parameter before passing it to 'snprintf' and subsequently executing it via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the 'servername' field. Successful exploitation allows for arbitrary command execution with the privileges of the web server, potentially leading to full system compromise. Public exploit code (PoC) is available.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-25: disclosed: Vulnerability reported via VulDB and GitHub PoC.
- 2026-05-25: advisory: CVE-2026-9454 published.