Impact
A weakness in the setUpgradeUboot routine of /cgi-bin/cstecgi.cgi in Totolink CA750-PoE 6.2c.510 permits an attacker to inject and execute operating system commands by manipulating the FileName argument. This flaw falls under the command injection category (CWE-77/78) and can lead to unauthorized control of the device, compromising confidentiality, integrity, and availability of the network it serves. The vulnerability is remote, meaning an attacker does not need local access. The CVSS score of 5.3 indicates moderate severity, but the public availability of exploit code raises the practical risk of abuse.
Affected Systems
This vulnerability affects Totolink CA750-PoE routers running firmware version 6.2c.510. No other product variants or versions are listed as impacted in the CNA data.
Risk and Exploitability
Because the flaw can be triggered via remote HTTP requests targeting the cstecgi.cgi endpoint, an attacker can send crafted requests to execute arbitrary shell commands on the device. The EPSS score of 3% indicates a low but non‑negligible probability of exploitation, and the public availability of proof‑of‑concept scripts further underscores the risk. The moderate CVSS score reflects the technical severity, while the potential operational impact depends on the attacker’s goals and the network topologies in which the device operates.
OpenCVE Enrichment