Impact
The vulnerability is located in the SetUnloadUserData function within the /cgi-bin/cstecgi.cgi script of the Totolink CA750‑PoE router firmware 6.2c.510. By manipulating the plugin_version request parameter, an attacker may inject arbitrary operating‑system commands, allowing remote execution of code on the device. This weakness corresponds to OS Command Injection (CWE‑77 and CWE‑78).
Affected Systems
The affected device is the Totolink CA750‑PoE router running firmware version 6.2c.510. No other products or versions are mentioned in the advisory.
Risk and Exploitability
The CVSS base score is 5.3, reflecting moderate severity, and the EPSS score is 11%, indicating a non‑negligible likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack may be launched remotely by sending a crafted HTTP request to the /cgi-bin/cstecgi.cgi endpoint; the exploit is publicly available and has been demonstrated in the wild. Remote execution of arbitrary commands threatens the device’s confidentiality, integrity, and availability for any network entity that can reach the endpoint.
OpenCVE Enrichment