Impact
This vulnerability is an OS command injection in the `setWebWlanIdx` parameter of the cstecgi.cgi interface on Totolink CA750-PoE routers. If an attacker is able to manipulate the webWlanIdx argument, they can execute arbitrary shell commands on the device. The ability to run system commands compromises confidentiality, integrity, and availability of the router’s firmware and other connected services, providing a pathway for remote code execution with potential full device control.
Affected Systems
The affected product is the Totolink CA750-PoE router running firmware version 6.2c.510. The vulnerability resides in the /cgi-bin/cstecgi.cgi component of the router’s setting handler. Only this specific firmware revision appears to be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity. The EPSS score is 2%, indicating a low but nonzero exploitation probability, and the vulnerability is publicly documented; publicly available exploits exist, indicating a realistic exploitation chance. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, with an attacker sending a crafted HTTP request carrying a malicious webWlanIdx value to the exposed CGI interface of the router.
OpenCVE Enrichment