CVE-2026-9531Active Exploitation

MEDIUMCVSS 2.1 · LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-26: 1Active Exploitation · 2026-05-26: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-26: 105-26
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • NerdieNews@NewsNerdie
    Active Exploitation

    Attackers are actively exploiting CVE-2026-9531 in Totolink CA750-PoE routers, enabling OS command injection. Patch now to prevent unauthorized access and potential full compromise. #NerdieNews #CyberSecurity #ThreatIntel https://t.co/rwo66Fmyh2

    Post summary

    Attackers are actively exploiting CVE‑2026‑9531 in Totolink CA750‑PoE routers via OS command injection; a patch is immediately recommended.

    0000046
    64 followersView on X

Explore more