OS Command Injection Vulnerability in Totolink CA750-PoE
CVE-2026-9533
Key Information:
Badges
What is CVE-2026-9533?
A vulnerability has been identified in the Totolink CA750-PoE, specifically within the recvUpgradeNewFw function in the cgi-bin/cstecgi.cgi file, part of the Setting Handler. This vulnerability allows for remote command injection through manipulation of the fwUrl and magicid parameters. Attackers can execute arbitrary commands on the device by sending specially crafted requests, potentially compromising the device's integrity and security. With the exploit now public, it is crucial for users to take immediate action to secure their devices.
Affected Version(s)
CA750-PoE 6.2c.510
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
