Junglewise Threat Intelligence

CVE-2026-9532: Totolink CA750-PoE command injection in setUploadUserData

CVE-2026-9532 · Severity: medium · CVSS 6.3 · Published 2026-05-26

Technologies: TOTOLINK CA750-PoE. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink CA750-PoE router, a device used to provide wireless networking and power over ethernet. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted request to the device's management interface. This could allow an unauthorized person to intercept network traffic, disrupt internet connectivity, or use the device as a foothold to attack other systems on the local network.

Technical details

An OS command injection vulnerability exists in the Totolink CA750-PoE firmware version 6.2c.510 within the 'setUploadUserData' function of the '/cgi-bin/cstecgi.cgi' component. The root cause is the improper neutralization of special elements in the 'FileName' argument, which is subsequently passed to a system shell without adequate validation. A remote attacker with low-level authentication can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) in the FileName field. Successful exploitation allows for arbitrary code execution with the privileges of the web server, potentially leading to a full system compromise. Public exploit code (PoC) demonstrating a telnet reverse shell has been disclosed.

Affected products

  • Totolink CA750-PoE 6.2c.510

Timeline

  • 2026-05-26: disclosed: Vulnerability and PoC publicly disclosed via GitHub and VulDB.
  • 2026-05-26: advisory: NVD published the CVE record.

References

Related threats