Report: CVE-2026-9534 - Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection

Report: CVE-2026-9534 - Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection

CVE ID :CVE-2026-9534 Published : May 26, 2026, 5:30 a.m. | 2 hours, 50 minutes ago Description :A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
May 26, 2026
Impact: command injection