CVE-2026-9534: Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection
Published May 26, 2026
·Updated
A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
1 affected component
TOTOLINK CA750-PoE=6.2c.510
Event History
May 26, 2026
CVE Published
via MITRE·05:30 AM
Data Sourced
via MITRE·05:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Dec 12, 58377
Event
via FIRST·09:25 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-9534?
The severity of CVE-2026-9534 is medium with a CVSS score of 6.3.
2
How can CVE-2026-9534 be exploited?
CVE-2026-9534 can be exploited through os command injection via the PIN argument in the setWiFiWpsConfig function.
3
What component is affected by CVE-2026-9534?
CVE-2026-9534 affects the Setting Handler component in the Totolink CA750-PoE device.
4
How do I fix CVE-2026-9534?
To fix CVE-2026-9534, update the Totolink CA750-PoE to the latest firmware version available.
5
Is remote exploitation possible for CVE-2026-9534?
Yes, CVE-2026-9534 can be exploited remotely.