Ghostwire

CVE-2026-9532: A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function...

MEDIUM CVSS 5.5

Published: May 26, 2026 | Last Modified: May 26, 2026

Description

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References