Junglewise Threat Intelligence

CVE-2026-9513: Totolink CA750-PoE OS command injection in NTPSyncWithHost

CVE-2026-9513 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: TOTOLINK CA750-PoE. Vendors: TOTOLINK.

Executive brief

Totolink CA750-PoE is a wireless access point used to provide network connectivity in business and home environments. A security vulnerability in its time synchronization feature allows an attacker with basic user access to take control of the device. By sending a specially crafted request, an attacker can execute unauthorized commands, potentially leading to a complete compromise of the device, interception of network traffic, or disruption of service.

Technical details

An OS command injection vulnerability exists in the Totolink CA750-PoE firmware version 6.2c.510. The flaw is located within the NTPSyncWithHost function in the /cgi-bin/cstecgi.cgi binary (specifically within system.so). The 'host_time' parameter is processed without sufficient sanitization before being passed to a system command execution call. A remote attacker with low-privileged authenticated access can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the host_time field. Successful exploitation allows for arbitrary command execution as the root user, as demonstrated by public proof-of-concept code that starts a telnet daemon.

Affected products

  • Totolink CA750-PoE 6.2c.510

Timeline

  • 2026-05-25: disclosed: Vulnerability disclosed via VulDB and GitHub PoC
  • 2026-05-25: advisory: CVE-2026-9513 assigned

References

Related threats