Executive brief
Totolink CA750-PoE is a wireless access point used to provide network connectivity in business and home environments. A security vulnerability in its time synchronization feature allows an attacker with basic user access to take control of the device. By sending a specially crafted request, an attacker can execute unauthorized commands, potentially leading to a complete compromise of the device, interception of network traffic, or disruption of service.
Technical details
An OS command injection vulnerability exists in the Totolink CA750-PoE firmware version 6.2c.510. The flaw is located within the NTPSyncWithHost function in the /cgi-bin/cstecgi.cgi binary (specifically within system.so). The 'host_time' parameter is processed without sufficient sanitization before being passed to a system command execution call. A remote attacker with low-privileged authenticated access can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the host_time field. Successful exploitation allows for arbitrary command execution as the root user, as demonstrated by public proof-of-concept code that starts a telnet daemon.
Affected products
- Totolink CA750-PoE 6.2c.510
Timeline
- 2026-05-25: disclosed: Vulnerability disclosed via VulDB and GitHub PoC
- 2026-05-25: advisory: CVE-2026-9513 assigned