Impact
A flaw exists in the setPasswordCfg function of the /cgi-bin/cstecgi.cgi script on the Totolink CA750-PoE router, allowing an attacker to inject operating system commands. The vulnerability is exploitable remotely with the manipulation of the admuser or admpass parameters, enabling an attacker to execute arbitrary commands with the privileges of the web interface process. This can lead to takeover of the device, data exfiltration, and potential entry into the broader network. The flaw represents an instance of CWE-77 and CWE-78, which involve OS command injection due to insecure handling of shell arguments.
Affected Systems
The vulnerability affects Totolink CA750-PoE routers running firmware version 6.2c.510. Users of this model should verify their installed version and identify whether the affected components are present.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is 3%, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the exploit is publicly released and can be deployed over the network, meaning that an attacker with network reach can perform the attack without physical access or sophisticated prerequisites.
OpenCVE Enrichment