Totolink CA750-PoE
- 6.2c.510
A command injection vulnerability has been identified in the TOTOLink CA750-PoE router running firmware version 6.2c.510. The issue arises in the Setting Handler component, specifically within the NTPSyncWithHost function of the cstecgi.cgi file. This vulnerability allows remote attackers to execute arbitrary operating system commands by manipulating the host_time argument. The exploit has been publicly disclosed and is available for use.
Exploitation of this vulnerability leads to unauthorized execution of operating system commands on the affected device, potentially allowing for further exploitation or manipulation of the device's functions.
To reproduce this vulnerability, send a POST request to the /cgi-bin/cstecgi.cgi endpoint. Include a crafted payload in the host_time parameter, such as a command to be executed by the system, wrapped in a specific format. The request should be made with a valid session cookie to authenticate the request.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.