CVE-2026-9514

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is directly passed by the attacker/so we can control the NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de seguridad ha sido detectada en Totolink CA750-PoE 6.2c.510. Se ve afectada la función setNetworkDiag del archivo /cgi-bin/cstecgi.cgi del componente Gestor de Configuración. La manipulación del argumento NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop es directamente pasada por el atacante/por lo que podemos controlar el NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop, lo que conduce a una inyección de comandos del sistema operativo. El ataque puede ser iniciado remotamente. El exploit ha sido divulgado públicamente y puede ser utilizado.

25 May 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-25 23:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-9514

Mitre link : CVE-2026-9514

CVE.ORG link : CVE-2026-9514


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')