CVE-2026-9532
Medium
Elevated severity or exploit probability.
CVSS base
6.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS — probability of exploitation (30 days)
10.8%
95.6th percentile
CISA KEV
Not listed
Weakness / dates
CWE-77
Published 2026-05-26 · modified 2026-07-23
Description
A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.