Executive brief
A vulnerability exists in the Totolink CA750-PoE router, a device used to provide wireless networking and Power-over-Ethernet connectivity. An attacker can exploit this flaw to take complete control of the router by executing unauthorized system commands. This could lead to the interception of network traffic, unauthorized access to the internal network, or a total disruption of internet services.
Technical details
An OS command injection vulnerability exists in the Totolink CA750-PoE router running firmware version 6.2c.510. The flaw is located within the 'setUnloadUserData' function in the 'cstecgi.cgi' binary (specifically within the upgrade.so library). The 'plugin_version' parameter is improperly sanitized before being passed to a system shell, allowing an authenticated attacker to inject arbitrary commands using backticks or shell metacharacters. A public exploit exists demonstrating the ability to start a telnet daemon with root shell access. The attack is reachable over the network, though it typically requires low-level authentication.
Affected products
- Totolink CA750-PoE 6.2c.510
Timeline
- 2026-05-26: advisory: NVD publication date