Description
A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is directly passed by the attacker/so we can control the NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-05-25
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the setNetworkDiag function exposed by the /cgi-bin/cstecgi.cgi script in Totolink CA750-PoE firmware 6.2c.510. Parameters such as NetDiagHost, NetDiagPingNum, NetDiagPingSize, NetDiagPingTimeOut, and NetDiagTracertHop are concatenated into operating‑system commands without validation, enabling an attacker to inject arbitrary shell commands via a crafted HTTP request. This flaw is a classic OS command injection (CWE‑77) and path‑injection style weakness (CWE‑78) that permits remote execution of commands on the device, potentially leading to full system compromise, data exfiltration, or service disruption. The description states that the attack can be initiated remotely and that the exploit has been publicly disclosed.

Affected Systems

The affected product is the Totolink CA750-PoE router, firmware 6.2c.510. No other vendors or product versions are listed as impacted in the CNA data. If the vendor offers newer releases, they should be examined for the presence of the same interface or a corrected implementation.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, but the nature of the flaw—remote command injection—raises the real‑world risk. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified; however, the flaw is publicly disclosed and not listed in the CISA KEV catalog, suggesting it may not yet be actively exploited in the wild. The attack vector is remote, and the attacker can trigger the vulnerability by sending a crafted HTTP request to the cstecgi.cgi endpoint. Successful exploitation grants the attacker full command‑line control over the router.

Generated by OpenCVE AI on May 26, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version that removes or sanitizes the setNetworkDiag parameters, following the vendor’s official release instructions.
  • If a firmware update is not yet available, block external access to the /cgi-bin/cstecgi.cgi endpoint using a firewall or network segmentation, ensuring only trusted internal management traffic can reach it.
  • Disable or restrict remote configuration and administration features on the device so that only local or authenticated users can reach the vulnerable interface, mitigating the risk of external exploitation.

Generated by OpenCVE AI on May 26, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 23:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is directly passed by the attacker/so we can control the NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Title Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
First Time appeared Totolink
Totolink ca750-poe
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:totolink:ca750-poe:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink ca750-poe
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink Ca750-poe
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-25T22:45:09.294Z

Reserved: 2026-05-25T15:08:52.477Z

Link: CVE-2026-9514

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T01:00:12Z

Weaknesses