Junglewise Threat Intelligence

CVE-2026-9476: Totolink A8000RU command injection in setPasswordCfg

CVE-2026-9476 · Severity: critical · CVSS 9.8 · Published 2026-05-25

Technologies: TOTOLINK A8000RU. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink A8000RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take full control of the router by sending a specially crafted request to its web management interface. This could allow an unauthorized user to intercept network traffic, disrupt internet service, or use the device as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the 'setPasswordCfg' function within the '/cgi-bin/cstecgi.cgi' component of the Totolink A8000RU router (firmware version 7.1cu.643_b20200521). The root cause is the improper neutralization of the 'admpass' argument, which is passed to the 'Uci_Set_Str' function and subsequently handled by 'CsteSystem' using 'snprintf' before being executed via 'execv()'. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters in the 'admpass' parameter. Successful exploitation results in arbitrary command execution with the privileges of the web server. A public exploit (PoC) is available.

Affected products

  • Totolink A8000RU 7.1cu.643_b20200521

Timeline

  • 2026-05-25: disclosed: Initial vulnerability disclosure and NVD publication

References

Related threats