Impact
The vulnerable function setUploadUserData in the /cgi-bin/cstecgi.cgi file of the Totolink CA750-PoE 6.2c.510 firmware allows an attacker to inject arbitrary operating‑system commands by manipulating the FileName parameter. This can lead to remote execution of commands on the device, compromising confidentiality, integrity, and availability of the network infrastructure. The flaw is identified as a CWE‑77 (OS Command Injection) and CWE‑78 (Command Injection).
Affected Systems
Affected systems include the Totolink CA750-PoE router running firmware version 6.2c.510. No higher versions were listed in the vulnerability data, so any device still on this firmware is vulnerable. The vulnerability is specific to the Setting Handler component.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score is 5%, indicating a low but non‑zero probability of exploitation; combined with public disclosure and remote nature, it suggests that exploitation could occur. The risk is moderate; however, no public exploit has been reported in the KEV catalog. Attackers would need network access to the device and the ability to call the cstecgi.cgi endpoint, which is commonly exposed to remote clients.
OpenCVE Enrichment