Junglewise Threat Intelligence

CVE-2026-9514: TOTOLink CA750-PoE OS command injection in setNetworkDiag

CVE-2026-9514 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: TOTOLINK CA750-PoE. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the TOTOLink CA750-PoE router, a device used to provide wireless networking and Power over Ethernet connectivity. An attacker can exploit a flaw in the device's network diagnostic tools to take complete control of the router. This could allow an unauthorized person to intercept network traffic, disrupt internet connectivity, or use the device as a foothold to attack other systems on the local network.

Technical details

An OS command injection vulnerability exists in the 'setNetworkDiag' function within the '/cgi-bin/cstecgi.cgi' component of TOTOLink CA750-PoE firmware version 6.2c.510. The vulnerability stems from improper neutralization of special elements in several parameters, including NetDiagHost, NetDiagPingNum, NetDiagPingSize, NetDiagPingTimeOut, and NetDiagTracertHop. A remote attacker with low privileges can provide crafted input (e.g., using backticks or command separators) that is directly passed to a system shell. Successful exploitation allows for arbitrary remote code execution (RCE) on the underlying operating system. A public exploit demonstrating a reverse shell via telnetd has been disclosed.

Affected products

  • TOTOLink CA750-PoE 6.2c.510

Timeline

  • 2026-05-25: disclosed: Vulnerability disclosed and CVE assigned
  • 2026-05-25: advisory: NVD published the advisory

References

Related threats