Junglewise Threat Intelligence

CVE-2026-9458: Totolink A8000RU OS command injection in setWanCfg

CVE-2026-9458 · Severity: critical · CVSS 9.8 · Published 2026-05-25

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity and manage local networks. An attacker can remotely take full control of the router by sending a specially crafted request to its web management interface. This could lead to the theft of sensitive data, interception of network traffic, or a complete shutdown of the internet service.

Technical details

An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setWanCfg' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability is rooted in the improper sanitization of the 'enabled' parameter, which is passed from the web interface to the 'Uci_Set_Str_By_Idx' function and eventually executed via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted JSON POST request containing shell metacharacters (e.g., backticks) in the 'enabled' field. Successful exploitation allows for arbitrary command execution with the privileges of the web server. A public proof-of-concept (PoC) is available.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-05-25: disclosed: Vulnerability disclosed via VulDB and NVD
  • 2026-05-25: advisory

References

Related threats