CVE 5.3 MEDIUM

Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection_CVE-2026-9511

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Basic Information

ID CVE-2026-9511
Source VulDB
Published May 25, 2026 at 22:00

Affected Product

Vendor Totolink
Product CA750-PoE
Version 6.2c.510
Affected Versions Totolink CA750-PoE 6.2c.510

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.