Junglewise Threat Intelligence

CVE-2026-9531: Totolink CA750-PoE command injection in setUpgradeUboot

CVE-2026-9531 · Severity: medium · CVSS 6.3 · Published 2026-05-26

Technologies: TOTOLINK CA750-PoE. Vendors: TOTOLINK.

Executive brief

A vulnerability exists in the Totolink CA750-PoE router, a device used to provide wireless networking and Power-over-Ethernet capabilities. An attacker can exploit this flaw to take full control of the device by executing unauthorized system commands. This could lead to the interception of network traffic, disruption of internet services, or use of the device as a foothold for further attacks on the internal network.

Technical details

An OS command injection vulnerability exists in the Totolink CA750-PoE firmware version 6.2c.510. The flaw is located within the 'setUpgradeUboot' function in the '/cgi-bin/cstecgi.cgi' handler, specifically due to improper neutralization of the 'FileName' argument. A remote attacker with low privileges can send a crafted POST request containing shell metacharacters (e.g., backticks) in the FileName parameter to execute arbitrary OS commands on the underlying system. Public exploit code demonstrates that this can be used to start a telnet daemon and gain root shell access.

Affected products

  • Totolink CA750-PoE 6.2c.510

Timeline

  • 2026-05-26: disclosed: Vulnerability details and PoC published on GitHub
  • 2026-05-26: advisory: NVD/VulDB advisory published

References

Related threats