CVE-2026-9534
published 2026-05-26CVE-2026-9534: A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting…
PriorityP354medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
1.80%
76.0th percentile
A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | ca750-poe | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wm4-fmvg-pxj4: A flaw has been found in Totolink CA750-PoE 6
ghsa_unreviewed·2026-05-26
CVE-2026-9534 [LOW] CWE-77 GHSA-2wm4-fmvg-pxj4: A flaw has been found in Totolink CA750-PoE 6
A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
VulDB
Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setWiFiWpsConfig PIN os command injection
vuldb·2026-05-25
CVE-2026-9534 [CRITICAL] Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setWiFiWpsConfig PIN os command injection
A vulnerability was found in Totolink CA750-PoE 6.2c.510. It has been declared as critical. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection.
This vulnerability is registered as CVE-2026-9534. It is possible to launch the attack remotely. Furthermore, an exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-26
Published