Totolink Ca750-Poe vulnerabilities
9 known vulnerabilities affecting totolink/ca750-poe.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM9
Vulnerabilities
Page 1 of 1
CVE-2026-9515P2MEDIUMCVSS 6.3v6.2c.5102026-05-26
CVE-2026-9515 [MEDIUM] CWE-77 CVE-2026-9515: A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function se
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument plugin_version results in os command injection. The attack may be launched remotely. The exploit is now public and may be used.
cvelistv5nvd
CVE-2026-9532P2MEDIUMCVSS 6.3v6.2c.5102026-05-26
CVE-2026-9532 [MEDIUM] CWE-77 CVE-2026-9532: A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is t
A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly an
nvd
CVE-2026-9514P2MEDIUMCVSS 6.3v6.2c.5102026-05-25
CVE-2026-9514 [MEDIUM] CWE-77 CVE-2026-9514: A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function
A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is directly passed by the attacker/so we can control the Net
cvelistv5nvd
CVE-2026-9534P2MEDIUMCVSS 6.3v6.2c.5102026-05-26
CVE-2026-9534 [MEDIUM] CWE-77 CVE-2026-9534: A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of
A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
nvd
CVE-2026-9533P2MEDIUMCVSS 6.3v6.2c.5102026-05-26
CVE-2026-9533 [MEDIUM] CWE-77 CVE-2026-9533: A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function re
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may b
nvd
CVE-2026-9531P2MEDIUMCVSS 6.3v6.2c.5102026-05-26
CVE-2026-9531 [MEDIUM] CWE-77 CVE-2026-9531: A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUb
A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could
nvd
CVE-2026-9511P3MEDIUMCVSS 6.3v6.2c.5102026-05-25
CVE-2026-9511 [MEDIUM] CWE-77 CVE-2026-9511: A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanI
A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
cvelistv5nvd
CVE-2026-9513P3MEDIUMCVSS 6.3v6.2c.5102026-05-25
CVE-2026-9513 [MEDIUM] CWE-77 CVE-2026-9513: A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSy
A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument host_time can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and
cvelistv5nvd
CVE-2026-9512P3MEDIUMCVSS 6.3v6.2c.5102026-05-25
CVE-2026-9512 [MEDIUM] CWE-77 CVE-2026-9512: A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the f
A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be initiated remotely. The exploit has been released to th
cvelistv5nvd