CVE-2026-9531: Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection
A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9531?
The severity of CVE-2026-9531 is classified as medium with a score of 6.3.
How do I fix CVE-2026-9531?
To fix CVE-2026-9531, update the Totolink CA750-PoE firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-9531?
CVE-2026-9531 is an OS command injection vulnerability affecting the setUpgradeUboot function.
Can CVE-2026-9531 be exploited remotely?
Yes, CVE-2026-9531 can be exploited remotely due to its nature of command injection.
What component is affected by CVE-2026-9531?
CVE-2026-9531 affects the Setting Handler component in the Totolink CA750-PoE device.