PT-2026-43193 · Totolink · Ca750-Poe

Buoy_Yes

·

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-9533

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9533

Affected Products

Ca750-Poe