Junglewise Threat Intelligence

CVE-2026-9533: Totolink CA750-PoE command injection in recvUpgradeNewFw

CVE-2026-9533 · Severity: medium · CVSS 6.3 · Published 2026-05-26

Technologies: TOTOLINK CA750-PoE. Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the Totolink CA750-PoE router, a device used to provide wireless networking and Power-over-Ethernet capabilities. An attacker can exploit this flaw to take control of the device by executing unauthorized commands. This could lead to a complete compromise of the network traffic passing through the router or a disruption of internet services.

Technical details

An OS command injection vulnerability exists in the Totolink CA750-PoE router running firmware version 6.2c.510. The flaw is located within the 'recvUpgradeNewFw' function in the '/cgi-bin/cstecgi.cgi' component (Setting Handler). The vulnerability stems from improper neutralization of special elements in the 'fwUrl' and 'magicid' parameters, which are passed directly to a system shell. A remote attacker with low privileges can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands on the underlying Linux operating system. A public exploit demonstrating a telnet reverse shell is available.

Affected products

  • Totolink CA750-PoE 6.2c.510

Timeline

  • 2026-05-26: disclosed: Vulnerability disclosed via VulDB and GitHub PoC
  • 2026-05-26: advisory: CVE-2026-9533 published

References

Related threats