TOTOLink CA750-PoE OS Command Injection Vulnerability

Vulnerability

An OS command injection vulnerability has been identified in the TOTOLink CA750-PoE router, specifically in version 6.2c.510. The issue arises in the Setting Handler component, within the 'recvUpgradeNewFw' function of the '/cgi-bin/cstecgi.cgi' file. The vulnerability can be exploited remotely by manipulating the 'fwUrl' and 'magicid' arguments, allowing attackers to execute arbitrary OS commands on the device.

Impact

Exploitation of this vulnerability leads to unauthorized execution of OS commands on the affected router, potentially allowing for further system compromise.

Reproduction

To reproduce this vulnerability, send a POST request to '/cgi-bin/cstecgi.cgi' with a payload that includes a crafted 'fwUrl' value designed to inject OS commands. The router will execute the injected command, such as opening a reverse shell via telnet.

Added: May 26, 2026, 5:22 PM
Updated: May 26, 2026, 5:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
9.6
threat
6.5
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.