PT-2026-43158 · Totolink · Ca750-Poe

Buoy_Yes

·

Published

2026-05-25

·

Updated

2026-05-25

·

CVE-2026-9515

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument plugin version results in os command injection. The attack may be launched remotely. The exploit is now public and may be used.

Exploit

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9515

Affected Products

Ca750-Poe