Description
A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-05-26
Score: 5.3 Medium
EPSS: 2.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in the setUpgradeUboot routine of /cgi-bin/cstecgi.cgi in Totolink CA750-PoE 6.2c.510 permits an attacker to inject and execute operating system commands by manipulating the FileName argument. This flaw falls under the command injection category (CWE-77/78) and can lead to unauthorized control of the device, compromising confidentiality, integrity, and availability of the network it serves. The vulnerability is remote, meaning an attacker does not need local access. The CVSS score of 5.3 indicates moderate severity, but the public availability of exploit code raises the practical risk of abuse.

Affected Systems

This vulnerability affects Totolink CA750-PoE routers running firmware version 6.2c.510. No other product variants or versions are listed as impacted in the CNA data.

Risk and Exploitability

Because the flaw can be triggered via remote HTTP requests targeting the cstecgi.cgi endpoint, an attacker can send crafted requests to execute arbitrary shell commands on the device. The EPSS score of 3% indicates a low but non‑negligible probability of exploitation, and the public availability of proof‑of‑concept scripts further underscores the risk. The moderate CVSS score reflects the technical severity, while the potential operational impact depends on the attacker’s goals and the network topologies in which the device operates.

Generated by OpenCVE AI on May 26, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version that removes the vulnerable setUpgradeUboot handler or patches the command‑injection flaw.
  • If a firmware update is not immediately available, limit external access to the cstecgi.cgi interface by configuring the device’s firewall or an upstream router to block all but trusted IP addresses.
  • Consider network segmentation to isolate the affected router from critical infrastructure, and regularly audit incoming traffic for anomalous command‑execution patterns.

Generated by OpenCVE AI on May 26, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 05:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Title Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection
First Time appeared Totolink
Totolink ca750-poe
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:totolink:ca750-poe:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink ca750-poe
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink Ca750-poe
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-26T04:45:14.640Z

Reserved: 2026-05-25T19:44:08.528Z

Link: CVE-2026-9531

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-26T05:16:19.367

Modified: 2026-05-26T05:16:19.367

Link: CVE-2026-9531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T16:00:11Z

Weaknesses