Executive brief
A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can remotely take full control of the router by sending a specially crafted request to its web management interface. This could lead to the theft of sensitive data, interception of network traffic, or a complete shutdown of the local network.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the /cgi-bin/cstecgi.cgi component. The vulnerability is located in the setOpenVpnCfg function (specifically sub_430C78), which fails to properly sanitize the 'port' and 'enabled' parameters before passing them to the CsteSystem function. The CsteSystem function eventually executes the input via execv(). A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary system commands. A public proof-of-concept demonstrating the creation of files on the filesystem is available.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-25: disclosed: Vulnerability reported via VulDB and NVD
- 2026-05-25: advisory