Junglewise Threat Intelligence

CVE-2026-9511: Totolink CA750-PoE OS command injection in setWebWlanIdx

CVE-2026-9511 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: TOTOLINK CA750-PoE. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink CA750-PoE, a wireless access point used for providing network connectivity. An attacker can exploit this flaw to take control of the device by executing unauthorized system commands. This could lead to a complete compromise of the device, allowing the attacker to intercept network traffic or disrupt operations.

Technical details

An OS command injection vulnerability exists in the Totolink CA750-PoE firmware version 6.2c.510. The flaw is located within the 'setWebWlanIdx' function in the '/cgi-bin/cstecgi.cgi' binary (specifically within global.so). The application fails to properly sanitize the 'webWlanIdx' (or 'PIN' in some contexts) parameter before passing it to a system shell. A remote attacker with low privileges can send a crafted POST request to execute arbitrary shell commands, such as starting a telnet daemon for persistent remote access. A public exploit (PoC) is available.

Affected products

  • Totolink CA750-PoE 6.2c.510

Timeline

  • 2026-05-25: disclosed: Initial disclosure and NVD publication

References

Related threats