OS Command Injection in Totolink CA750-PoE by Totolink
CVE-2026-9512
Key Information:
Badges
What is CVE-2026-9512?
A security vulnerability has been found in the Totolink CA750-PoE model 6.2c.510, specifically in the setPasswordCfg function located in the /cgi-bin/cstecgi.cgi file within the Setting Handler component. This flaw allows attackers to manipulate the admuser and admpass parameters, leading to OS command injection. The exploit can be executed remotely, posing a significant risk as it has already been made public. Organizations using this product must implement immediate measures to secure their devices against potential exploitation.
Affected Version(s)
CA750-PoE 6.2c.510
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
