TOTOLINK A6000R Command Injection Vulnerability in reset_wifi Function

Vulnerability

A command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in firmware version V1.0.1-B20201211.2000. The vulnerability arises in the reset_wifi function, where the devname parameter can be manipulated to inject and execute arbitrary commands on the device.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

The vulnerability can be reproduced by sending a GET request to the /cgi-bin/luci/admin/mtk/wifi/reset/ endpoint. The devname parameter should be injected with a command, such as 'ls>111.txt', which will be executed on the device. This injection can be verified by checking the result of the executed command.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.