Totolink CA750-PoE
- 6.2c.510
A command injection vulnerability has been identified in the TOTOLink CA750-PoE router running firmware version 6.2c.510. The issue resides in the Setting Handler component, specifically within the setNetworkDiag function of the cstecgi.cgi file. The vulnerability allows remote attackers to execute arbitrary operating system commands by manipulating several network diagnostic parameters that are directly passed to the system without proper validation.
Exploitation of this vulnerability leads to unauthorized execution of operating system commands on the affected device, potentially allowing for a full system compromise.
To reproduce this vulnerability, send a POST request to the /cgi-bin/cstecgi.cgi endpoint with a crafted payload that includes the desired command in the NetDiagHost parameter. The router will execute the injected command, such as opening a reverse shell via telnet.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.