CVE-2026-9533: Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9533?
CVE-2026-9533 has a medium severity rating of 6.3.
How do I fix CVE-2026-9533?
To mitigate CVE-2026-9533, update the Totolink CA750-PoE firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-9533?
CVE-2026-9533 is an OS command injection vulnerability.
What component is affected by CVE-2026-9533?
CVE-2026-9533 affects the Setting Handler function recvUpgradeNewFw in the cstecgi.cgi file.
Can CVE-2026-9533 be exploited remotely?
Yes, CVE-2026-9533 can be exploited remotely due to its nature of command injection.