Junglewise Threat Intelligence

CVE-2026-9455: Totolink A8000RU OS command injection in UploadOpenVpnCert

CVE-2026-9455 · Severity: critical · CVSS 9.8 · Published 2026-05-25

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted request to its web management interface. This could lead to the interception of network traffic, unauthorized access to connected devices, or a total disruption of internet services.

Technical details

An OS command injection vulnerability exists in the UploadOpenVpnCert function within the /cgi-bin/cstecgi.cgi component of Totolink A8000RU firmware version 7.1cu.643_b20200521. The root cause is the improper neutralization of the 'FileName' parameter, which is passed to snprintf and subsequently executed via the CsteSystem function using execv(). A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the FileName argument. Successful exploitation allows for arbitrary command execution with the privileges of the web server. A public exploit (PoC) has been disclosed.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-05-25: disclosed: Vulnerability details and PoC published on GitHub.
  • 2026-05-25: advisory: CVE-2026-9455 published.

References

Related threats