Executive brief
A critical security vulnerability has been identified in the Totolink A8000RU wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted web request. This could lead to the theft of sensitive data, interception of internet traffic, or a total disruption of network services.
Technical details
An OS command injection vulnerability exists in the Totolink A8000RU router (firmware version 7.1cu.643_b20200521) within the 'setParentalRules' function of the '/cgi-bin/cstecgi.cgi' component. The vulnerability is caused by improper neutralization of the 'enable' parameter, which is passed to the 'Uci_Set_Str' function and eventually executed via 'execv()' through the 'CsteSystem' function. A remote, unauthenticated attacker can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the 'enable' field. Successful exploitation allows for full system compromise with root privileges. Public exploit code (PoC) is available.
Affected products
- Totolink A8000RU 7.1cu.643_b20200521
Timeline
- 2026-05-25: disclosed: Vulnerability disclosed via VulDB and GitHub PoC
- 2026-05-25: advisory: NVD published the CVE record