PT-2025-18652 · Totolink · Totolink Cpe Cp900

Published

2025-04-01

·

Updated

2025-05-03

·

CVE-2025-44837

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK CPE CP900 version 6.3c.1144 B20190715
Description A command injection issue was found in the CloudSrvUserdataVersionCheck function, allowing attackers to execute arbitrary commands via a crafted request. This is possible through the url or magicid parameters.
Recommendations For TOTOLINK CPE CP900 version 6.3c.1144 B20190715, consider disabling the CloudSrvUserdataVersionCheck function until a patch is available. Restrict access to the url and magicid parameters in the affected API endpoint to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06194
CVE-2025-44837

Affected Products

Totolink Cpe Cp900