Executive brief
A vulnerability exists in the Totolink CA750-PoE, a wireless access point used for providing network connectivity. An attacker can exploit this flaw to take control of the device by executing unauthorized system commands. This could lead to a complete compromise of the device, allowing the attacker to intercept network traffic or disrupt operations.
Technical details
An OS command injection vulnerability exists in the Totolink CA750-PoE firmware version 6.2c.510. The flaw is located within the 'setWebWlanIdx' function in the '/cgi-bin/cstecgi.cgi' binary (specifically within global.so). The application fails to properly sanitize the 'webWlanIdx' (or 'PIN' in some contexts) parameter before passing it to a system shell. A remote attacker with low privileges can send a crafted POST request to execute arbitrary shell commands, such as starting a telnet daemon for persistent remote access. A public exploit (PoC) is available.
Affected products
- Totolink CA750-PoE 6.2c.510
Timeline
- 2026-05-25: disclosed: Initial disclosure and NVD publication