CVE-2026-9511
published 2026-05-25CVE-2026-9511: A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component…
PriorityP353medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
1.06%
60.7th percentile
A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | ca750-poe | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
cvelistv5v4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wv96-774q-mh29: A vulnerability was identified in Totolink CA750-PoE 6
ghsa_unreviewed·2026-05-26
CVE-2026-9511 [LOW] CWE-77 GHSA-wv96-774q-mh29: A vulnerability was identified in Totolink CA750-PoE 6
A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
CVEList
Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection
cvelistv5·2026-05-25·CVSS 5.3
CVE-2026-9511 [MEDIUM] CWE-78 Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection
Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection
A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Timeline: 2026-05-25: Advisory disclosed; 2026-05-25: VulDB entry created; 2026-05-25: VulDB entry last update
VulDB
Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setWebWlanIdx webWlanIdx os command injection (EUVD-2026-31760)
vuldb·2026-05-25
CVE-2026-9511 [CRITICAL] Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setWebWlanIdx webWlanIdx os command injection (EUVD-2026-31760)
A vulnerability described as critical has been identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection.
This vulnerability is referenced as CVE-2026-9511. It is possible to launch the attack remotely. Furthermore, an exploit is available.
No detection rules found.
Nuclei
SmarterMail - Remote Code Execution
nuclei·CVSS 9.3
CVE-2026-24423 [CRITICAL] SmarterMail - Remote Code Execution
SmarterMail - Remote Code Execution
SmarterTools SmarterMail < build 9511 contains an unauthenticated remote code execution caused by malicious OS command execution via ConnectToHub API method, letting remote attackers execute arbitrary commands, exploit requires no authentication.
Template:
id: CVE-2026-24423
info:
name: SmarterMail - Remote Code Execution
author: jyoti369
severity: critical
description: |
SmarterTools SmarterMail < build 9511 contains an unauthenticated remote code execution caused by malicious OS command execution via ConnectToHub API method, letting remote attackers execute arbitrary commands, exploit requires no authentication.
impact: |
Remote attackers can execute arbitrary OS commands, potentially leading to full system compromise.
remediation: |
Update to buil
Huntress
Huntress Catches SmarterMail Account Takeover Leading to RCE
blogs_huntress·2026-01-22·CVSS 10.0
CVE-2026-23760 Huntress Catches SmarterMail Account Takeover Leading to RCE
## Background / Summary
The Huntress DE&TH (Detection Engineering and Threat Hunting) Team has observed in-the-wild exploitation of a privileged account takeover vulnerability ( CVE-2026-23760 ) in SmarterTool’s SmarterMail application that has resulted in successful remote code execution. Our testing has indicated that versions of SmarterMail prior to Build 9511 are vulnerable. Users of SmarterMail are urged to upgrade to the latest version, Build 9511 , released on January 15, 2026.
Note that this is separate from the ongoing mass exploitation of CVE-2025-52691, an arbitrary file upload vulnerability in SmarterMail that also leads to remote code execution. At the time of writing Huntress contacted SmarterTools and held off publishing whilst CVE-2026-23760 was published as it was alread
Wiz
CVE-2026-23760 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-23760 [CRITICAL] CVE-2026-23760 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23760 :
SmarterTools SmarterMail vulnerability analysis and mitigation
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
Source
2026-05-25
Published