Description
A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2026-05-25: | Advisory disclosed |
| 2026-05-25: | VulDB entry created |
| 2026-05-25: | VulDB entry last update |
Credits
Buoy_yes (VulDB User)
References
vuldb.com/vuln/365561 (VDB-365561 | Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection)
vuldb.com/vuln/365561/cti (VDB-365561 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/813938 (Submit #813938 | TOTOLink CA750-PoE V6.2c.510 Command Injection)
github.com/wudipjq/my_vuln/blob/main/totolink4/vuln_57/57.md
www.totolink.net/