CVE-2026-9512: Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection
A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9512?
CVE-2026-9512 has a medium severity rating of 6.3.
What is the impact of CVE-2026-9512?
CVE-2026-9512 allows for OS command injection through the setPasswordCfg function in the Totolink CA750-PoE.
How do I fix CVE-2026-9512?
To mitigate CVE-2026-9512, update the firmware of the Totolink CA750-PoE to a version that addresses this vulnerability.
Is CVE-2026-9512 easily exploitable?
Yes, CVE-2026-9512 can be exploited due to its low access complexity and requires only the manipulation of specific parameters.
What software is affected by CVE-2026-9512?
CVE-2026-9512 affects the Totolink CA750-PoE, specifically version 6.2c.510.