Totolink CA750-PoE
- 6.2c.510
An OS command injection vulnerability has been identified in the TOTOLink CA750-PoE router, specifically in version 6.2c.510. The issue arises in the Setting Handler component, within the 'recvUpgradeNewFw' function of the '/cgi-bin/cstecgi.cgi' file. The vulnerability can be exploited remotely by manipulating the 'fwUrl' and 'magicid' arguments, allowing attackers to execute arbitrary OS commands on the device.
Exploitation of this vulnerability leads to unauthorized execution of OS commands on the affected router, potentially allowing for further system compromise.
To reproduce this vulnerability, send a POST request to '/cgi-bin/cstecgi.cgi' with a payload that includes a crafted 'fwUrl' value designed to inject OS commands. The router will execute the injected command, such as opening a reverse shell via telnet.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.