Executive brief
A security vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and local networking. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted web request. This could lead to the interception of network traffic, unauthorized access to the local network, or a total disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the /cgi-bin/cstecgi.cgi component. The vulnerability is located in the UploadFirmwareFile function (specifically sub_4328D0), where the 'FileName' parameter is processed using __sprintf_chk without proper sanitization before being passed to a system execution function (CsteSystem/execv). A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the FileName argument. Successful exploitation results in arbitrary command execution as the root user. Proof-of-concept code has been publicly disclosed.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-25: disclosed: Vulnerability details and PoC published on GitHub
- 2026-05-25: advisory: CVE-2026-9457 published by VulDB/NVD