Description
A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-05-25
Score: 5.3 Medium
EPSS: 2.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the setPasswordCfg function of the /cgi-bin/cstecgi.cgi script on the Totolink CA750-PoE router, allowing an attacker to inject operating system commands. The vulnerability is exploitable remotely with the manipulation of the admuser or admpass parameters, enabling an attacker to execute arbitrary commands with the privileges of the web interface process. This can lead to takeover of the device, data exfiltration, and potential entry into the broader network. The flaw represents an instance of CWE-77 and CWE-78, which involve OS command injection due to insecure handling of shell arguments.

Affected Systems

The vulnerability affects Totolink CA750-PoE routers running firmware version 6.2c.510. Users of this model should verify their installed version and identify whether the affected components are present.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score is 3%, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the exploit is publicly released and can be deployed over the network, meaning that an attacker with network reach can perform the attack without physical access or sophisticated prerequisites.

Generated by OpenCVE AI on May 26, 2026 at 15:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to a firmware version that resolves the command‑injection flaw.
  • Verify that the firmware validates and sanitizes the admuser and admpass inputs, mitigating command injection per CWE‑77 and CWE‑78.
  • Limit remote access to the cgi handler by disabling outside‑world access or restricting the relevant ports to trusted IPs.
  • Change default administrative credentials and enforce strong passwords.

Generated by OpenCVE AI on May 26, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Title Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection
First Time appeared Totolink
Totolink ca750-poe
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:totolink:ca750-poe:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink ca750-poe
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink Ca750-poe
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-26T12:37:15.451Z

Reserved: 2026-05-25T15:08:43.704Z

Link: CVE-2026-9512

cve-icon Vulnrichment

Updated: 2026-05-26T12:37:11.299Z

cve-icon NVD

Status : Received

Published: 2026-05-25T23:16:34.073

Modified: 2026-05-25T23:16:34.073

Link: CVE-2026-9512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T15:45:08Z

Weaknesses